From: René Scharfe Date: Sat, 06 Dec 2025 13:21:06 GMT Subject: [PATCH v2 0/5] ban mktemp(3) Message-ID: <64e62623-b911-4ddd-a481-05191853c0a6@web.de> In-Reply-To: <784f495a-4b1a-4acf-96cd-599243ef9e27@web.de> mktemp(3) is insecure and POSIX.1-2008 no longer specifies it. Stop using it. Changes since v1: - add comment regarding return values of git_mkdstemps_mode() - add patch to drop trivialized gitmkdtemp() wrapper: add git_mkdtemp() compat: use git_mkdtemp() compat: remove mingw_mktemp() banned.h: ban mktemp(3) compat: remove gitmkdtemp() Makefile | 1 - banned.h | 3 +++ compat/mingw-posix.h | 3 --- compat/mingw.c | 12 ------------ compat/mkdtemp.c | 8 -------- compat/posix.h | 3 +-- contrib/buildsystems/CMakeLists.txt | 4 ---- meson.build | 2 +- wrapper.c | 21 +++++++++++++++++++-- wrapper.h | 2 ++ 10 files changed, 26 insertions(+), 33 deletions(-) delete mode 100644 compat/mkdtemp.c Range-diff against v1: 1: 830e6375aa ! 1: 413131caf6 wrapper: add git_mkdtemp() @@ wrapper.c: int xmkstemp(char *filename_template) #define TMP_MAX 16384 -int git_mkstemps_mode(char *pattern, int suffix_len, int mode) ++/* ++ * Returns -1 on error, 0 if it created a directory, or an open file ++ * descriptor to the created regular file. ++ */ +static int git_mkdstemps_mode(char *pattern, int suffix_len, int mode, bool dir) { static const char letters[] = 2: 889903eaa2 = 2: f8850b2a92 compat: use git_mkdtemp() 3: 255b97254f = 3: 6986b4b6bf compat: remove mingw_mktemp() 4: 8300d2e224 = 4: f34252f411 banned.h: ban mktemp(3) -: ---------- > 5: d106855a23 compat: remove gitmkdtemp() -- 2.52.0