git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] gitk: use mktemp -d to avoid predictable temporary directories

From
Pat Thoyts <patthoyts@users.sourceforge.net>
Date
Jun 15, 2014, 07:51 UTC
Message-ID
<87k38ir4p0.fsf@red.patthoyts.tk>
In-Reply-To
<1402695828-91537-1-git-send-email-davvid@gmail.com>
David Aguilar <davvid@gmail.com> writes:
Show 33 quoted lines
>gitk uses a predictable ".gitk-tmp.$PID" pattern when generating
>a temporary directory.
>
>Use "mktemp -d .gitk-tmp.XXXXXX" to harden gitk against someone
>seeding /tmp with files matching the pid pattern.
>
>Signed-off-by: David Aguilar <davvid@gmail.com>
>---
>This issue was brought up during the first review of the previous patch
>back in 2009.
>
>http://thread.gmane.org/gmane.comp.version-control.git/132609/focus=132748
>
>This is really [PATCH 2/2] and should be applied on top of my previous
>gitk patch.
>
> gitk | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
>diff --git a/gitk b/gitk
>index 82293dd..dd2ff63 100755
>--- a/gitk
>+++ b/gitk
>@@ -3502,7 +3502,8 @@ proc gitknewtmpdir {} {
> 	} else {
> 	    set tmpdir $gitdir
> 	}
>-	set gitktmpdir [file join $tmpdir [format ".gitk-tmp.%s" [pid]]]
>+	set gitktmpformat [file join $tmpdir ".gitk-tmp.XXXXXX"]
>+	set gitktmpdir [exec mktemp -d $gitktmpformat]
> 	if {[catch {file mkdir $gitktmpdir} err]} {
> 	    error_popup "[mc "Error creating temporary directory %s:" $gitktmpdir] $err"
> 	    unset gitktmpdir

This is a problem on Windows where we will not have mktemp. In Tcl 8.6 the file command acquired a "file tempfile" command to help with this kind of issue (https://www.tcl.tk/man/tcl8.6/TclCmd/file.htm#M39) but for older versions we should probably stick with the existing pattern at least on Windows.

-- 
Pat Thoyts                            http://www.patthoyts.tk/
PGP fingerprint 2C 6E 98 07 2C 59 C8 97  10 CE 11 E6 04 E0 B9 DD
Previous: Paul MackerrasNext: brian m. carlson
Message 3 of 9 in “gitk: use mktemp -d to avoid predictable temporary directories”
  1. gitk: use mktemp -d to avoid predictable temporary directoriesDavid Aguilar, Jun 13, 2014
  2. Paul MackerrasJun 15, 2014
  3. Pat ThoytsJun 15, 2014
  4. brian m. carlsonJun 15, 2014
  5. David AguilarJun 15, 2014
  6. brian m. carlsonJun 15, 2014
  7. Junio C HamanoJun 16, 2014
  8. David AguilarJun 19, 2014
  9. Thomas BraunJun 16, 2014

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.