Skip to content

ext/session: Close save handler when session encoding fails - #24022

Open
iliaal wants to merge 1 commit into
php:PHP-8.6from
iliaal:fix/session-encode-null-close-86
Open

iliaal wants to merge 1 commit into
php:PHP-8.6from
iliaal:fix/session-encode-null-close-86

Conversation

@iliaal

@iliaal iliaal commented Sep 30, 2026

Copy link
Copy Markdown
Member

Since 86b4921, a session that cannot be encoded (for example a $_SESSION key containing a pipe with the php serializer) makes session_write_close() return early without closing the save handler, so the files handler keeps the session file locked until the end of the request and concurrent requests for that session block on it. This only affects PHP-8.6 and master; 8.5 and earlier always reached the close. The handler is now closed on that return, like the rest of the function and session_regenerate_id() already do, including when an exception is pending, since the engine does not invoke a user close() callback in that state anyway.

/cc @Girgias

Since 86b4921, php_session_save_current_state() returns without calling
the save handler's close callback when the serializer returns NULL, e.g. for
a $_SESSION key containing '|'. session_write_close() still returns true, but
the files handler keeps its LOCK_EX on the session file until request
shutdown, blocking concurrent requests for the same session, and a user
handler extending SessionHandler has its close() run at shutdown after the
session is gone. Close the handler on that return as the rest of the function
and session_regenerate_id() do; with an exception pending the engine already
refuses to call a user close() callback.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant