git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] gitk: use mktemp -d to avoid predictable temporary directories

From
Thomas Braun <thomas.braun@virtuell-zuhause.de>
Date
Jun 16, 2014, 11:40 UTC
Message-ID
<539ED793.7050409@virtuell-zuhause.de>
In-Reply-To
<87k38ir4p0.fsf@red.patthoyts.tk>
Am 15.06.2014 09:51, schrieb Pat Thoyts:
Show 41 quoted lines
> David Aguilar <davvid@gmail.com> writes:
> 
>> gitk uses a predictable ".gitk-tmp.$PID" pattern when generating
>> a temporary directory.
>>
>> Use "mktemp -d .gitk-tmp.XXXXXX" to harden gitk against someone
>> seeding /tmp with files matching the pid pattern.
>>
>> Signed-off-by: David Aguilar <davvid@gmail.com>
>> ---
>> This issue was brought up during the first review of the previous patch
>> back in 2009.
>>
>> http://thread.gmane.org/gmane.comp.version-control.git/132609/focus=132748
>>
>> This is really [PATCH 2/2] and should be applied on top of my previous
>> gitk patch.
>>
>> gitk | 3 ++-
>> 1 file changed, 2 insertions(+), 1 deletion(-)
>>
>> diff --git a/gitk b/gitk
>> index 82293dd..dd2ff63 100755
>> --- a/gitk
>> +++ b/gitk
>> @@ -3502,7 +3502,8 @@ proc gitknewtmpdir {} {
>> 	} else {
>> 	    set tmpdir $gitdir
>> 	}
>> -	set gitktmpdir [file join $tmpdir [format ".gitk-tmp.%s" [pid]]]
>> +	set gitktmpformat [file join $tmpdir ".gitk-tmp.XXXXXX"]
>> +	set gitktmpdir [exec mktemp -d $gitktmpformat]
>> 	if {[catch {file mkdir $gitktmpdir} err]} {
>> 	    error_popup "[mc "Error creating temporary directory %s:" $gitktmpdir] $err"
>> 	    unset gitktmpdir
> 
> This is a problem on Windows where we will not have mktemp. In Tcl 8.6
> the file command acquired a "file tempfile" command to help with this
> kind of issue (https://www.tcl.tk/man/tcl8.6/TclCmd/file.htm#M39) but
> for older versions we should probably stick with the existing pattern at
> least on Windows.

We could of course add mktemp from http://www.mktemp.org to msysgit. I can do that if required.

In mingwgitDevEnv we already have the the need for mktemp, and a msys package, so this is also not a problem.

Previous: David Aguilar
Message 9 of 9 in “gitk: use mktemp -d to avoid predictable temporary directories”
  1. gitk: use mktemp -d to avoid predictable temporary directoriesDavid Aguilar, Jun 13, 2014
  2. Paul MackerrasJun 15, 2014
  3. Pat ThoytsJun 15, 2014
  4. brian m. carlsonJun 15, 2014
  5. David AguilarJun 15, 2014
  6. brian m. carlsonJun 15, 2014
  7. Junio C HamanoJun 16, 2014
  8. David AguilarJun 19, 2014
  9. Thomas BraunJun 16, 2014

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.