Re: Session cache, lock and write
| From: | Yasuo Ohgaki | Date: | Thu, 14 Nov 2013 19:54:38 +0000 |
| Subject: | Re: Session cache, lock and write | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-70122@lists.php.net to get a copy of this message | ||
Hi all,
On Fri, Nov 15, 2013 at 4:42 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> Session module can be faster in several ways.
>
> It can ignore writing session data when session data is not changed.
> It also can remove reading session data by caching as most web
> servers support keep alive. Current session save handlers lock
> session data, but it could be unlocked.
>
> There are many applications that transnational consistency of session
> data is not mandatory.
>
> Session module could have ini settings
> - session.read_cache = int (by default 0 = no cache. 5 for 5 seconds)
> Read cache will be updated if session data has changed.
> - session.lock = On/Off (On by default. Some save handlers already have
> this)
> - session.write_short_circuit = On/Off (Off by default)
>
> Users may verify save handler feature by viewing phpinfo() and
> source code level compatibility will be kept.
>
> These features boost web application performance a lot by ignoring
> session data consistency. It's just like transnational vs.
> non-transnational SQL.
>
> session.read_cache and session.lock may be consolidated since
> enabling session.read_cache disables session.lock. There are slight
> difference between them but it may be ignored.
> (With session.lock=On, writes from other web server(PHP) can be blocked
> even when session.read_cache=5, but reading session cache on the same
> keep alive session will not be blocked, for example.)
>
> Any comments?
>
I also would like to add "session deletion delay" to mitigate session
deletion
race condition by adding deletion time in session data. (i.e
session_regenerate_id(true)
may create multiple valid sessions. This can be mitigated by having this)
session.deletion_delay = int (by default 0 = delete immediately. 10 for 10
sec later)
If there is $_SESSION['__SESSION_EXPIRE__'] and expired, new session ID is
created
automatically.
I would like to hear comments for this also.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net