Re: Session cache, lock and write

From: Date: Thu, 14 Nov 2013 19:54:38 +0000
Subject: Re: Session cache, lock and write
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-70122@lists.php.net to get a copy of this message
Hi all, On Fri, Nov 15, 2013 at 4:42 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > Session module can be faster in several ways. > > It can ignore writing session data when session data is not changed. > It also can remove reading session data by caching as most web > servers support keep alive. Current session save handlers lock > session data, but it could be unlocked. > > There are many applications that transnational consistency of session > data is not mandatory. > > Session module could have ini settings > - session.read_cache = int (by default 0 = no cache. 5 for 5 seconds) > Read cache will be updated if session data has changed. > - session.lock = On/Off (On by default. Some save handlers already have > this) > - session.write_short_circuit = On/Off (Off by default) > > Users may verify save handler feature by viewing phpinfo() and > source code level compatibility will be kept. > > These features boost web application performance a lot by ignoring > session data consistency. It's just like transnational vs. > non-transnational SQL. > > session.read_cache and session.lock may be consolidated since > enabling session.read_cache disables session.lock. There are slight > difference between them but it may be ignored. > (With session.lock=On, writes from other web server(PHP) can be blocked > even when session.read_cache=5, but reading session cache on the same > keep alive session will not be blocked, for example.) > > Any comments? > I also would like to add "session deletion delay" to mitigate session deletion race condition by adding deletion time in session data. (i.e session_regenerate_id(true) may create multiple valid sessions. This can be mitigated by having this) session.deletion_delay = int (by default 0 = delete immediately. 10 for 10 sec later) If there is $_SESSION['__SESSION_EXPIRE__'] and expired, new session ID is created automatically. I would like to hear comments for this also. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#70122) next »