php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #23405 fopen() fails when SessionID is added as GET-Param
Submitted: 2003-04-29 07:59 UTC Modified: 2003-04-29 09:01 UTC
From: helmut dot chang at tuivelsminne dot at Assigned:
Status: Not a bug Package: Session related
PHP Version: 4.3.2RC2 OS: SuSE Linux 8.0
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: helmut dot chang at tuivelsminne dot at
New email:
PHP Version: OS:

 

 [2003-04-29 07:59 UTC] helmut dot chang at tuivelsminne dot at
Using Apache 1.3.27 with mod_ssl and mod_php4 as DSO, fopen() fails when adding SessionID as GET-Parameter:

test1.php:

<?php
session_start();

$fp = fopen('http://domain.tld/test2.php?'.session_name().'='.session_id(), 'r');
?>

test2.php:

<?php
session_start();
?>

Calling 'test1.php' makes the server busy for the max_execution_time and then producing the message:

Warning: fopen(http://cmit.dev.is-it-on.at/test2.php?PHPSESSID=d438afbea1645cab6e557bd7cb396165): failed to open stream: HTTP request failed! main:443 for SSL protocol L library ound (st in /daten/www-data/cmIT/htdocs/test.php on line 4

The part between 'HTTP request failed!' and 'in /daten/...' changes each time, sometimes producing somewhat looking like binary data.

Changing test1.php to:

$fp = fopen('http://domain.tld/test2.php', 'r');

doesn't cause any problems. The same, when using other GET-Params:

$fp = fopen('http://domain.tld/test2.php?test=TRUE', 'r');

works also.

I just compiled a new PHP, using the latest Snapshot, after reading the Bugreports #19051, #22937, #20759,..., but it seems to me, the problem is not exact the same:

fopen works ALWAYS with 'normal' HTTP-URLs and NEVER works when adding the SessionID.

Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2003-04-29 09:01 UTC] wez@php.net
If both your local script and the remote script are running on the same machine and are using the files session module, you need to be aware that the session file is locked for the duration of the session;
You are encountering a classic deadlock here because the first script holds the lock while the second attempts to acquire it.  Since the first can't release the lock until it has finished, and it can't finish until the second has acquired the lock, you get the timeout message.

Why don't you include() a local file? It is *much* more resource efficient and is not subject to these issues.

I'm marking this as bogus, as it is the expected behaviour.
(Changing it will break sessions for everybody).
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 05:00:01 2026 UTC