Re: [PATCH v2] contrib: added git-diffall
- From
Stefano Lattarini <stefano.lattarini@gmail.com>
- Date
- Feb 23, 2012, 09:56 UTC
- Message-ID
- <4F460D45.7000804@gmail.com>
- In-Reply-To
- <7vipiy8m5q.fsf@alter.siamese.dyndns.org>
Hello everybody. Hope you don't mind 2 cents from an outsider ...
On 02/23/2012 12:48 AM, Junio C Hamano wrote:
Show 16 quoted lines
>
> Tim Henigan <tim.henigan@gmail.com> writes:
>
>> +# mktemp is not available on all platforms (missing from msysgit)
>> +# Use a hard-coded tmp dir if it is not available
>> +tmp="$(mktemp -d -t tmp.XXXXXX 2>/dev/null)" || {
>> + tmp=/tmp/git-diffall-tmp
>> +}
>
> It would not withstand malicious attacks, but doing
>
> tmp=/tmp/git-diffall-tmp.$$
>
> would at least protect you from accidental name crashes better in the
> fallback codepath.
>Maybe this would be enough to withstand malicious attacks (even if not denial-of-service attacks):
# mktemp is not available on all platforms (missing from msysgit)
tmp=$(mktemp -d -t tmp.XXXXXX 2>/dev/null) || {
tmp=/tmp/git-diffall-tmp.$$
mkdir "$tmp" || fatal "couldn't create temporary directory"
}> >> +mkdir -p "$tmp" >
At which point this should be removed, of course.
Regards, Stefano