fix: prevent session_start() lock errors with Memcached handler#10209
Open
jalexiscv wants to merge 1 commit into
Open
fix: prevent session_start() lock errors with Memcached handler#10209jalexiscv wants to merge 1 commit into
jalexiscv wants to merge 1 commit into
Conversation
Fixes codeigniter4#7604 When using Memcached as session handler with concurrent AJAX requests, session_start() could throw 'Unable to clear session lock record' warning. Two issues contributed: 1. MemcachedHandler::close() did not reset $this->lockKey and $this->lock after deleting the lock, unlike releaseLock(). This could leave PHP's session handler in an inconsistent lock state between requests. 2. PHP has a known limitation with custom session handlers where lock cleanup warnings can occur during concurrent access. Using error suppression on session_start() prevents these from becoming fatal errors in production. Changes: - MemcachedHandler::close(): reset lockKey and lock after delete - Session::startSession(): add @ to session_start() with explanatory comment about PHP's custom session handler limitation Note: RedisHandler and DatabaseHandler already properly managed lock state in their close() methods. Ref: codeigniter4#7604
|
Hi there, jalexiscv! 👋 Thank you for sending this PR! We expect the following in all Pull Requests (PRs).
Important We expect all code changes or bug-fixes to be accompanied by one or more tests added to our test suite to prove the code works. If pull requests do not comply with the above, they will likely be closed. Since we are a team of volunteers, we don't have any more time to work See https://github.com/codeigniter4/CodeIgniter4/blob/develop/contributing/pull_request.md Sincerely, the mergeable bot 🤖 |
paulbalandan
requested changes
May 18, 2026
Member
paulbalandan
left a comment
There was a problem hiding this comment.
A couple of tests and a changelog entry here are needed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Fixes #7604 - [Memcached] session_start(): Unable to clear session lock record
Problem
When using Memcached as session handler with concurrent AJAX requests,
session_start()could throw:This occurred due to two issues:
MemcachedHandler::close()called$this->memcached->delete($this->lockKey)but did NOT reset$this->lockKey = nulland$this->lock = false. This left the lock state inconsistent between requests, unlikereleaseLock()which properly resets these properties. Compare withRedisHandler::close()which usesreleaseLock()correctly.PHP has a known limitation with custom session handlers where concurrent access can trigger lock cleanup warnings even when the handler behaves correctly.
Solution
MemcachedHandler::close() - Reset lock state after delete to match releaseLock() behavior:
Session::startSession() - Use error suppression on session_start() as a safety net for PHP's custom handler limitation, with an explanatory comment:
@session_start();Changes
system/Session/Handlers/MemcachedHandler.php- reset lock state in close()system/Session/Session.php- error suppression on session_start()Notes
@suppression is a well-known workaround used by other frameworks for this PHP limitationRef: #7604
Closes #7604