Bug->Doc #75047 [Opn]: session_regenerate_id fails with redis

From: Date: Tue, 05 Sep 2017 23:00:45 +0000
Subject: Bug->Doc #75047 [Opn]: session_regenerate_id fails with redis
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-14956@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75047&edit=1 ID: 75047 Updated by: yohgaki@php.net Reported by: bartosz at kibilko dot pl Summary: session_regenerate_id fails with redis Status: Open -Type: Bug +Type: Documentation Problem -Package: Unknown/Other Function +Package: Session related Operating System: Ubuntu / Docker Container PHP Version: 7.0.22 -Assigned To: +Assigned To: yohgaki Block user comment: N Private report: N New Comment: Make this a doc bug. Previous Comments: ------------------------------------------------------------------------ [2017-09-05 21:32:45] yohgaki@php.net It seems I missed to document it code, too :( I'll update both UPGRADING and comment in the code. ------------------------------------------------------------------------ [2017-09-05 21:00:02] yohgaki@php.net I missed to write upgrading note to UPGRADING. However, I wrote enough comments to ttps://github.com/php/php-src/blob/master/ext/session/mod_files.c for native session save handler developers as a reference implementation, but the comment is deleted by someone else. I guess that's the reason why phpredis misses required code... ------------------------------------------------------------------------ [2017-09-05 09:39:23] yohgaki@php.net BTW, this is caused due to session_regenerate_id() behavior change from PHP 7.0. PHP 5.6 and less - Old session data is not saved and creates new session without validating SID PHP 7.0 and up - Old session data is saved and creates new session with SID validation. From PHP 7.0, session save handlers are required not only to implement SID validation function, but also create session data either at "open" or "read" to make SID validation work. I might have missed this in UPGRADING. ------------------------------------------------------------------------ [2017-09-05 08:40:26] yohgaki@php.net > The reason that this problem exists is because PHP doesn't create the key > in Redis if it doesn't exist. As a work-around, you need to create a key if > one doesn't exist in the read() function of your session handler class. > This removed the problem from my error logs: Thank you for useful info. I take a look at the code for session save handler "read" and "write" in phpredis. https://github.com/phpredis/phpredis/blob/develop/redis_session.c#L342 https://github.com/phpredis/phpredis/blob/develop/redis_session.c#L402 Session "read" does not send write command to redis for empty get, so it seems this is phpredis session save handler bug. Save handlers are supposed to create session ID data entry either - open or - read When data is created is depends on underlying storage. For instance, "files" cannot create session data file with "read" since file is created when it is opened. On the other hand, storage like redis/postgresql/etc cannot create session data with "open", but "read". "open" is supposed to open connection to db. "open" may create session data entry, though. It seems this is phpredis issue, please close this bug if you get this fixed. If not, please let me know issue is in session. ------------------------------------------------------------------------ [2017-09-05 06:20:40] ray at rayxis dot com I'm also experiencing this in php 7.1.8. The reason that this problem exists is because PHP doesn't create the key in Redis if it doesn't exist. As a work-around, you need to create a key if one doesn't exist in the read() function of your session handler class. This removed the problem from my error logs: public function read ($key) { // Get the session data and extend the expiration. $nkey = $this->prefix . $key; read: $data = $this->sess->get($nkey); // If nothing exists, create it first because PHP has a bug. :( if (!$data) { $this->write($key,TRUE); goto read; } $this->sess->expire($key, getenv('SESSTTL')); // Return the result. return $data; } ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=75047 -- Edit this bug report at https://bugs.php.net/bug.php?id=75047&edit=1

« previous php.doc.bugs (#14956) next »