Bug #73461 [Asn]: Segfault when always regenerating session id from read handler [PHP 7 only]
| From: | yohgaki@php.net | Date: | Mon, 07 Nov 2016 23:17:54 +0000 |
| Subject: | Bug #73461 [Asn]: Segfault when always regenerating session id from read handler [PHP 7 only] | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-14086@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73461&edit=1
ID: 73461
Updated by: yohgaki@php.net
Reported by: love at sickpeople dot se
Summary: Segfault when always regenerating session id from
read handler [PHP 7 only]
Status: Assigned
Type: Bug
Package: Documentation problem
PHP Version: 7.1.0RC5
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
5.6 does not crash because it does not what it should do.
Previous Comments:
------------------------------------------------------------------------
[2016-11-07 20:31:16] love at sickpeople dot se
@Yohgaki: is it known why this does *not* crash in 5.6? I'm asking since there are no
protection against this in 5.6 but yet no crash occures.
------------------------------------------------------------------------
[2016-11-05 21:26:29] yohgaki@php.net
> Possible solution by session module is to limit number of handler calls. Does any of us feel
> this is preferred?
I'll add documentation, but I'll also add new state "session is in save handler"
to prevent infinite calls because I realized that this is required so that session_create_id() to be
usable in create_sid() save handler. (I was expecting user to generate new session ID by their own
while session is active, but using session_create_id() is handy)
I think this should be in PHP7.1 (not 7.0), so I'll prepare the patch soon.
------------------------------------------------------------------------
[2016-11-05 17:30:38] yohgaki@php.net
This kind of save handler abuse is trivial.
e.g.
function sess($foo) {
sess($foo);
}
Another example is
https://3v4l.org/Cj76q
I don't think abusive code protection worths to implement, at least by session module. Making
this a documentation problem. (BTW, session_regenerate_id() calls all handlers to do the job
correctly. So it does not limited to read() handler, but all handlers.)
Possible solution by core is to excessive recursive call detection like Python, or stack limit reach
detection like Ruby.
Possible solution by session module is to limit number of handler calls. Does any of us feel this is
preferred?
------------------------------------------------------------------------
[2016-11-05 08:30:21] laruence@php.net
stack overflow
------------------------------------------------------------------------
[2016-11-04 17:17:13] love at sickpeople dot se
Description:
------------
The code below segfaults in PHP 7.x including PHP 7.1 RC5.
Basically this is a segfault due to infinite recursion and I know there has been reports about that
before. I created this bug for one main reason: this crash does NOT occur in PHP 5.x, including
5.6.27. It "appeared" in PHP 7.0.
Please see demo here: https://3v4l.org/Lc1cX
Test script:
---------------
session_set_save_handler ('sess', 'sess', 'sess_read',
'sess', 'sess', 'sess');
session_start ();
Function sess ($foo = 'foo') { return true; }
Function sess_read ($id)
{
session_regenerate_id (false);
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73461&edit=1