git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: fix mktemp (remove mktemp ;)

From
DLDavid Lang <david.lang@digitalinsight.com>
Date
Apr 17, 2005, 01:03 UTC
Message-ID
<Pine.LNX.4.62.0504161801030.22652@qynat.qvtvafvgr.pbz>
In-Reply-To
<20050417005757.GB15608@redhat.com>

set your umask to make things only writeable by the same user. then create a new directory (it will fail with an error if the directory already exists)

now you can create files in this directory without having to worry about other users makeing trouble for you (they can't create symlinks in this directory)

David Lang
On Sat, 16 Apr 2005, Dave Jones wrote:
Show 44 quoted lines
> Date: Sat, 16 Apr 2005 20:57:57 -0400
> From: Dave Jones <davej@redhat.com>
> To: Paul Jackson <pj@sgi.com>
> Cc: pasky@ucw.cz, git@vger.kernel.org, mj@ucw.cz
> Subject: Re: fix mktemp (remove mktemp ;)
> 
> On Sat, Apr 16, 2005 at 05:44:09PM -0700, Paul Jackson wrote:
> > Dave wrote:
> > > mktemp is being used here to provide randomness in the filename,
> > > not just a uniqueness.
> >
> > Ok - useful point.
> >
> > How about:
> >
> > 	t=${TMPDIR:-/usr/tmp}/gitdiff.$$.$RANDOM
>
> pid is still predictable by watching ps output, $RANDOM is one of 32768
> numbers, so it's still feasable to predict the result.
> $RANDOM$RANDOM is better, and gets a little closer to mktemp strength randomness.
>
> > > all an attacker has to do is create 65535 symlinks in /usr/tmp
> > And how about if I removed the tmp files at the top:
> >
> > 	t=${TMPDIR:-/usr/tmp}/gitdiff.$$.$RANDOM
> > 	trap 'rm -fr $t.?; trap 0; exit 0' 0 1 2 3 15
> > 	rm -fr $t.?
> >
> > 	... rest of script ...
>
> Racy, though the chance of creating x thousand symlinks in such a small
> window probably makes it a non-issue.
>
> Actually.. http://www.linuxsecurity.com/content/view/115462/151/
> has some interesting bits on temp dir creation without mktemp.
> See section 3.4 onwards.
>
> 		Dave
>
> -
> To unsubscribe from this list: send the line "unsubscribe git" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
>
-- 
There are two ways of constructing a software design. One way is to make it so simple that there are obviously no deficiencies. And the other way is to make it so complicated that there are no obvious deficiencies.
  -- C.A.R. Hoare
Previous: Dave JonesNext: Paul Jackson
Message 17 of 25 in “fix mktemp (remove mktemp ;)”
  1. fix mktemp (remove mktemp ;)Paul Jackson, Apr 16, 2005
  2. missing mkdir -p flag in gitdiff-doPaul Jackson, Apr 16, 2005
  3. optimize gitdiff-do scriptPaul Jackson, Apr 16, 2005
  4. Petr BaudisApr 16, 2005
  5. Paul JacksonApr 17, 2005
  6. Paul JacksonApr 18, 2005
  7. Petr BaudisApr 18, 2005
  8. Paul JacksonApr 18, 2005
  9. Paul JacksonMay 10, 2005
  10. Jan-Benedict GlawApr 16, 2005
  11. Paul JacksonApr 16, 2005
  12. Petr BaudisApr 16, 2005
  13. Paul JacksonApr 17, 2005
  14. Dave JonesApr 17, 2005
  15. Paul JacksonApr 17, 2005
  16. Dave JonesApr 17, 2005
  17. David LangApr 17, 2005
  18. Paul JacksonApr 17, 2005
  19. Brian O'MahoneyApr 17, 2005
  20. Paul JacksonApr 17, 2005
  21. Erik van KonijnenburgApr 17, 2005
  22. Paul JacksonApr 17, 2005
  23. Herbert XuApr 18, 2005
  24. Paul JacksonApr 18, 2005
  25. Florian WeimerApr 18, 2005

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.