Bug #73461 [Asn->Csd]: Segfault when always regenerating session id from read handler [PHP 7 only]

From: Date: Wed, 16 Nov 2016 05:14:56 +0000
Subject: Bug #73461 [Asn->Csd]: Segfault when always regenerating session id from read handler [PHP 7 only]
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-14107@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73461&edit=1 ID: 73461 Updated by: krakjoe@php.net Reported by: love at sickpeople dot se Summary: Segfault when always regenerating session id from read handler [PHP 7 only] -Status: Assigned +Status: Closed Type: Bug Package: Documentation problem PHP Version: 7.1.0RC5 Assigned To: yohgaki Block user comment: N Private report: N New Comment: Automatic comment on behalf of yohgaki Revision: http://git.php.net/?p=php-src.git;a=commit;h=7b29c3fba6678ea84285aa60b2494cc79f388bbb Log: Revert "Fix Bug #73461" Previous Comments: ------------------------------------------------------------------------ [2016-11-07 23:17:54] yohgaki@php.net 5.6 does not crash because it does not what it should do. ------------------------------------------------------------------------ [2016-11-07 20:31:16] love at sickpeople dot se @Yohgaki: is it known why this does *not* crash in 5.6? I'm asking since there are no protection against this in 5.6 but yet no crash occures. ------------------------------------------------------------------------ [2016-11-05 21:26:29] yohgaki@php.net > Possible solution by session module is to limit number of handler calls. Does any of us feel > this is preferred? I'll add documentation, but I'll also add new state "session is in save handler" to prevent infinite calls because I realized that this is required so that session_create_id() to be usable in create_sid() save handler. (I was expecting user to generate new session ID by their own while session is active, but using session_create_id() is handy) I think this should be in PHP7.1 (not 7.0), so I'll prepare the patch soon. ------------------------------------------------------------------------ [2016-11-05 17:30:38] yohgaki@php.net This kind of save handler abuse is trivial. e.g. function sess($foo) { sess($foo); } Another example is https://3v4l.org/Cj76q I don't think abusive code protection worths to implement, at least by session module. Making this a documentation problem. (BTW, session_regenerate_id() calls all handlers to do the job correctly. So it does not limited to read() handler, but all handlers.) Possible solution by core is to excessive recursive call detection like Python, or stack limit reach detection like Ruby. Possible solution by session module is to limit number of handler calls. Does any of us feel this is preferred? ------------------------------------------------------------------------ [2016-11-05 08:30:21] laruence@php.net stack overflow ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=73461 -- Edit this bug report at https://bugs.php.net/bug.php?id=73461&edit=1

« previous php.doc.bugs (#14107) next »