Skip to content

[Session] Truncate session file after successful write - #23653

Open
iliaal wants to merge 1 commit into
php:PHP-8.4from
iliaal:fix/session-write-truncate-84
Open

[Session] Truncate session file after successful write#23653
iliaal wants to merge 1 commit into
php:PHP-8.4from
iliaal:fix/session-write-truncate-84

Conversation

@iliaal

@iliaal iliaal commented Sep 10, 2026

Copy link
Copy Markdown
Member

The files session save handler truncated the session file to zero before writing, so a short or failed write returned failure with the previous data already gone. It now writes first and truncates to the new length only after the full buffer lands.

The files save handler ftruncated the session file to 0 before writing,
so a failed or short write returned FAILURE with the previous session
data already destroyed. Write first and truncate the old tail to the new
length only after the full buffer was written successfully. Sibling
audit: PS_WRITE_FUNC/PS_UPDATE_FUNC callers and the read path are
unaffected; the empty-write destroy path truncates identically.
Comment on lines +50 to +53
foreach (glob($dir . '/sess_*') as $f) {
@unlink($f);
}
@rmdir($dir);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Add --CLEAN-- and remove the defensive cleanup at the beginning?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants