Skip to content

[Session] Truncate session file after successful write - #23653

Open
iliaal wants to merge 1 commit into
php:PHP-8.4from
iliaal:fix/session-write-truncate-84
Open

[Session] Truncate session file after successful write#23653
iliaal wants to merge 1 commit into
php:PHP-8.4from
iliaal:fix/session-write-truncate-84

Conversation

@iliaal

@iliaal iliaal commented Sep 10, 2026

Copy link
Copy Markdown
Member

The files session save handler truncated the session file to zero before writing, so a short or failed write returned failure with the previous data already gone. It now writes first and truncates to the new length only after the full buffer lands.

Comment on lines +50 to +53
foreach (glob($dir . '/sess_*') as $f) {
@unlink($f);
}
@rmdir($dir);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Add --CLEAN-- and remove the defensive cleanup at the beginning?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Moved into --CLEAN--. The save path is a fixed name under __DIR__ now so the clean script can find it, which also drops the need for the upfront unlink loop.

Comment on lines +36 to +37
pcntl_signal(SIGXFSZ, SIG_IGN);
var_dump(posix_setrlimit(POSIX_RLIMIT_FSIZE, 16, POSIX_RLIMIT_INFINITY));

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What the hell does this do?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It caps the file size so the next session write fails, with SIGXFSZ ignored so the process survives it. The 16 was the wrong number: that gives a short write, which still clobbers the head of the file, so the test could only compare sizes. At 0 nothing lands at all, and the test now compares contents.

The files save handler ftruncated the session file to 0 before writing,
so a write that failed returned FAILURE with the previous session data
already destroyed. Write first and truncate the old tail to the new
length only after the full buffer was written successfully. Sibling
audit: PS_WRITE_FUNC/PS_UPDATE_FUNC callers and the read path are
unaffected; the empty-write destroy path truncates identically.
@iliaal
iliaal force-pushed the fix/session-write-truncate-84 branch from 4ca4585 to 870a4b2 Compare September 11, 2026 11:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants