Re: [PATCH] Do _not_ call unlink on a directory
- From
- Scott Lamb <slamb@slamb.org>
- Date
- Jul 16, 2007, 19:05 UTC
- Message-ID
- <469BC17D.60806@slamb.org>
- In-Reply-To
- <vpqd4yss1vo.fsf@bauges.imag.fr>
Matthieu Moy wrote:
Show 19 quoted lines
> Thomas Glanzmann <sithglan@stud.uni-erlangen.de> writes: > > I believe you still have a race condition if ... > >> - if (len > state->base_dir_len && state->force && !unlink(buf) && !mkdir(buf, 0777)) >> - continue; > > ... buf exists here as a file ... > >> if (!stat(buf, &st) && S_ISDIR(st.st_mode)) >> continue; /* ok */ > > ... and became a directory here. > >> + if (len > state->base_dir_len && state->force && !unlink(buf) && !mkdir(buf, 0777)) >> + continue; > > But that's quite unlikely to happen. And I have no fix to propose. >
If arbitrary other tasks are running, the only way to be absolutely certain you're not calling unlink() in a directory is to never call unlink().
SUS describes a safe remove(), but Solaris's implementation contains the same race:
http://src.opensolaris.org/source/xref/pef/phase_I/usr/src/lib/libc/port/gen/rename.c
so I think this patch is the best that can be done.
Best regards, Scott
-- Scott Lamb <http://www.slamb.org/>