Skip to content

ext/session: Close save handler when session encoding fails - #424

Closed
iliaal wants to merge 9 commits into
PHP-8.6from
fix/session-encode-null-close-86
Closed

iliaal wants to merge 9 commits into
PHP-8.6from
fix/session-encode-null-close-86

Conversation

@iliaal

@iliaal iliaal commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Since 86b4921 (php#21181), php_session_save_current_state() returns without calling the save handler's close callback when the serializer returns NULL, for example for a $_SESSION key containing '|' under the php serializer. session_write_close() still returns true, but the files handler keeps its LOCK_EX until request shutdown, so concurrent requests for the same session block, and a user SessionHandler's close() only runs at shutdown. The handler is now closed on that path when no exception is pending; with an exception pending the behavior is unchanged, since running the user close handler then is what was rejected on php#22622.

PHP-8.4 and PHP-8.5 are unaffected: they write an empty payload and always reach s_close. No NEWS entry, as the regression never shipped in a release.

orlitzky and others added 9 commits September 30, 2026 15:55
…vars

When invoking the PHP in a subprocess, TEST_PHP_EXECUTABLE_ESCAPED is
preferable to PHP_BINARY, because the former can be set to ensure that
the just-built (often development) php gets used rather than a system
install. In addition, TEST_PHP_EXTRA_ARGS should be passed to this
interpreter.

Closes phpGH-22414
This test goes to some trouble to ensure that it uses the config of
the just-built (often development) PHP rather than the system
one. There already exist environment variables to facilitate this
however -- TEST_PHP_EXECUTABLE and TEST_PHP_EXTRA_ARGS -- so let's use
them.

Closes phpGH-22405
* PHP-8.4:
  ext/soap/tests/bugs/bug62900.phpt: make use of TEST_PHP_ vars
  sapi/cli/tests/php_cli_server_ipv6_error_message.phpt: use TEST_PHP_ vars
Commit 2ecafd4 updates one of the curl ./configure tests to use
strncmp(), but that function may not be defined unless string.h is
included. We add it here.

Closes phpGH-23208
* PHP-8.5:
  ext/curl/config.m4: include string.h for test using strncmp()
  ext/soap/tests/bugs/bug62900.phpt: make use of TEST_PHP_ vars
  sapi/cli/tests/php_cli_server_ipv6_error_message.phpt: use TEST_PHP_ vars
dl() modules are MODULE_TEMPORARY. Their function records are freed at
request shutdown, but zend_flf_functions keeps those pointers for the
process lifetime. A later request can match the stale handler address
and use the freed record. Temporary modules leave the frameless info
unset, so the call uses the ordinary internal path.

Closes phpGH-24008
* PHP-8.4:
  Zend: Skip frameless registration for temporary modules
* PHP-8.5:
  Zend: Skip frameless registration for temporary modules
Since 86b4921, php_session_save_current_state() returns without calling
the save handler's close callback when the serializer returns NULL, e.g. for
a $_SESSION key containing '|'. session_write_close() still returns true, but
the files handler keeps its LOCK_EX on the session file until request
shutdown, blocking concurrent requests for the same session, and a user
handler extending SessionHandler has its close() run at shutdown after the
session is gone. Close the handler on that return as the rest of the function
and session_regenerate_id() do; with an exception pending the engine already
refuses to call a user close() callback.
@iliaal
iliaal force-pushed the fix/session-encode-null-close-86 branch from 63c4c8e to 16c4d8d Compare September 30, 2026 15:31
@iliaal

iliaal commented Sep 30, 2026

Copy link
Copy Markdown
Owner Author

Promoted upstream as php#24022.

@iliaal iliaal closed this Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants