git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] gitk: use mktemp -d to avoid predictable temporary directories

From
David Aguilar <davvid@gmail.com>
Date
Jun 13, 2014, 21:43 UTC
Message-ID
<1402695828-91537-1-git-send-email-davvid@gmail.com>

gitk uses a predictable ".gitk-tmp.$PID" pattern when generating a temporary directory.

Use "mktemp -d .gitk-tmp.XXXXXX" to harden gitk against someone seeding /tmp with files matching the pid pattern.

Signed-off-by: David Aguilar <davvid@gmail.com>
---
This issue was brought up during the first review of the previous patch
back in 2009.
http://thread.gmane.org/gmane.comp.version-control.git/132609/focus=132748

This is really [PATCH 2/2] and should be applied on top of my previous gitk patch.

 gitk | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/gitk b/gitk
index 82293dd..dd2ff63 100755
--- a/gitk
+++ b/gitk
@@ -3502,7 +3502,8 @@ proc gitknewtmpdir {} {
 	} else {
 	    set tmpdir $gitdir
 	}
-	set gitktmpdir [file join $tmpdir [format ".gitk-tmp.%s" [pid]]]
+	set gitktmpformat [file join $tmpdir ".gitk-tmp.XXXXXX"]
+	set gitktmpdir [exec mktemp -d $gitktmpformat]
 	if {[catch {file mkdir $gitktmpdir} err]} {
 	    error_popup "[mc "Error creating temporary directory %s:" $gitktmpdir] $err"
 	    unset gitktmpdir
-- 
2.0.0.257.g75cc6c6
Next: Paul Mackerras
Message 1 of 9 in “gitk: use mktemp -d to avoid predictable temporary directories”
  1. gitk: use mktemp -d to avoid predictable temporary directoriesDavid Aguilar, Jun 13, 2014
  2. Paul MackerrasJun 15, 2014
  3. Pat ThoytsJun 15, 2014
  4. brian m. carlsonJun 15, 2014
  5. David AguilarJun 15, 2014
  6. brian m. carlsonJun 15, 2014
  7. Junio C HamanoJun 16, 2014
  8. David AguilarJun 19, 2014
  9. Thomas BraunJun 16, 2014

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.