Skip to content

[Session] Truncate session file after successful write - #278

Open
iliaal wants to merge 1 commit into
PHP-8.4from
fix/session-write-truncate-84
Open

[Session] Truncate session file after successful write#278
iliaal wants to merge 1 commit into
PHP-8.4from
fix/session-write-truncate-84

Conversation

@iliaal

@iliaal iliaal commented Aug 24, 2026

Copy link
Copy Markdown
Owner

The files session save handler truncated the session file to 0 before writing new data, so a failed or short write (RLIMIT_FSIZE with SIGXFSZ ignored, for example) made ps_files_write() return FAILURE while the previous session data was already gone. ps_files_write() now writes first and truncates to the new length only after the full buffer lands, so failed writes leave prior data intact. A regression test reproduces the loss via posix_setrlimit(POSIX_RLIMIT_FSIZE); PS_WRITE_FUNC, PS_UPDATE_TIMESTAMP_FUNC and PS_DESTROY_FUNC were audited and behave identically. Closes aph-er5.

@iliaal iliaal closed this Aug 24, 2026
@iliaal iliaal reopened this Aug 24, 2026
The files save handler ftruncated the session file to 0 before writing,
so a failed or short write returned FAILURE with the previous session
data already destroyed. Write first and truncate the old tail to the new
length only after the full buffer was written successfully. Sibling
audit: PS_WRITE_FUNC/PS_UPDATE_FUNC callers and the read path are
unaffected; the empty-write destroy path truncates identically.
@iliaal
iliaal force-pushed the fix/session-write-truncate-84 branch 2 times, most recently from 846773a to f1dedf0 Compare August 26, 2026 12:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant