The Short Answer
Yes, a read-only session still blocks other requests. In Yii's default configuration, latency is not caused by the write operation itself, but by the exclusive lock acquired the moment the session is opened. Any concurrent request attempting to access the same session ID will queue and wait until the first request releases that lock.
How Session Locking Works in Yii
Yii typically relies on PHP's native files session handler. To prevent data corruption from race conditions (where two requests modify the same session data simultaneously), PHP implements a locking mechanism:
- Lock Acquisition: When
session_start() is called, PHP opens the session file and places an exclusive lock on it.
- Blocking: If a second request arrives with the same session ID, it also calls
session_start(). Because the first request holds the lock, the second request pauses execution entirely until the lock is available.
- Lock Release: The lock is released only when the script finishes execution or when
session_write_close() is explicitly called.
Impact of Lazy Loading and Auto-Start
Disabling auto-start or initiating the session lazily does not eliminate the lock; it only defers it. The blocking behavior begins the instant the session is started, regardless of whether you intend to read or write data. If you delay the session start until the end of a request, you avoid blocking other requests for the duration of the page load, but you lose access to session data during the request.
Latency and Data Volume
The latency observed is generally not proportional to the amount of data written. The delay is a result of the waiting period (the time the first request spends holding the lock), not the I/O time required to write the file to disk.
Verification and Mitigation
To verify this behavior in your environment, you can use a simple sleep test:
// In a controller action
public function actionTest() {
// Session starts automatically in Yii
sleep(10);
return "Finished";
}
If you trigger this action and immediately attempt to load another page in the same browser session, the second page will hang for 10 seconds.
Recommended Resolutions
- Explicit Release: Call
session_write_close() (or the Yii equivalent via the session component) as soon as you no longer need to modify session data. This releases the lock for other concurrent requests.
- Change Handler: For high-concurrency workloads, switch from
FileSession to DbSession or RedisSession. While some database handlers still implement locking, Redis-based handlers often provide more granular control or non-blocking options.
Diagnostic Detail Needed: To provide a more specific configuration recommendation, please confirm if you are using the default yii\web\Session component or a custom session class.