git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2 0/5] ban mktemp(3)

From
René Scharfe <l.s.r@web.de>
Date
Dec 6, 2025, 13:21 UTC
Message-ID
<64e62623-b911-4ddd-a481-05191853c0a6@web.de>
In-Reply-To
<784f495a-4b1a-4acf-96cd-599243ef9e27@web.de>

mktemp(3) is insecure and POSIX.1-2008 no longer specifies it. Stop using it.

Changes since v1:
- add comment regarding return values of git_mkdstemps_mode()
- add patch to drop trivialized gitmkdtemp()
  wrapper: add git_mkdtemp()
  compat: use git_mkdtemp()
  compat: remove mingw_mktemp()
  banned.h: ban mktemp(3)
  compat: remove gitmkdtemp()
 Makefile                            |  1 -
 banned.h                            |  3 +++
 compat/mingw-posix.h                |  3 ---
 compat/mingw.c                      | 12 ------------
 compat/mkdtemp.c                    |  8 --------
 compat/posix.h                      |  3 +--
 contrib/buildsystems/CMakeLists.txt |  4 ----
 meson.build                         |  2 +-
 wrapper.c                           | 21 +++++++++++++++++++--
 wrapper.h                           |  2 ++
 10 files changed, 26 insertions(+), 33 deletions(-)
 delete mode 100644 compat/mkdtemp.c
Range-diff against v1:
1:  830e6375aa ! 1:  413131caf6 wrapper: add git_mkdtemp()
    @@ wrapper.c: int xmkstemp(char *filename_template)
      #define TMP_MAX 16384
      
     -int git_mkstemps_mode(char *pattern, int suffix_len, int mode)
    ++/*
    ++ * Returns -1 on error, 0 if it created a directory, or an open file
    ++ * descriptor to the created regular file.
    ++ */
     +static int git_mkdstemps_mode(char *pattern, int suffix_len, int mode, bool dir)
      {
      	static const char letters[] =
2:  889903eaa2 = 2:  f8850b2a92 compat: use git_mkdtemp()
3:  255b97254f = 3:  6986b4b6bf compat: remove mingw_mktemp()
4:  8300d2e224 = 4:  f34252f411 banned.h: ban mktemp(3)
-:  ---------- > 5:  d106855a23 compat: remove gitmkdtemp()
-- 
2.52.0
Previous: Jeff KingNext: René Scharfe
Message 13 of 19 in “ban mktemp(3)”
  1. 0/4 ban mktemp(3)René Scharfe, Dec 3, 2025
  2. 1/4 wrapper: add git_mkdtemp()René Scharfe, Dec 3, 2025
  3. Chris TorekDec 4, 2025
  4. Junio C HamanoDec 5, 2025
  5. 2/4 compat: use git_mkdtemp()René Scharfe, Dec 3, 2025
  6. Jeff KingDec 3, 2025
  7. René ScharfeDec 5, 2025
  8. Jeff KingDec 6, 2025
  9. Junio C HamanoDec 5, 2025
  10. 3/4 compat: remove mingw_mktemp()René Scharfe, Dec 3, 2025
  11. 4/4 banned.h: ban mktemp(3)René Scharfe, Dec 3, 2025
  12. Jeff KingDec 3, 2025
  13. 0/5 ban mktemp(3)René Scharfe, Dec 6, 2025
  14. 1/5 wrapper: add git_mkdtemp()René Scharfe, Dec 6, 2025
  15. 2/5 compat: use git_mkdtemp()René Scharfe, Dec 6, 2025
  16. 3/5 compat: remove mingw_mktemp()René Scharfe, Dec 6, 2025
  17. 4/5 banned.h: ban mktemp(3)René Scharfe, Dec 6, 2025
  18. 5/5 compat: remove gitmkdtemp()René Scharfe, Dec 6, 2025
  19. Jeff KingDec 8, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.