Zsh Mailing List Archive
Messages sorted by:
Reverse Date,
Date,
Thread,
Author
Re: [PATCH] Re: Insecure tempfile creation
- X-seq: zsh-workers 34167
- From: Bart Schaefer <schaefer@xxxxxxxxxxxxxxxx>
- To: Zsh hackers list <zsh-workers@xxxxxxx>
- Subject: Re: [PATCH] Re: Insecure tempfile creation
- Date: Thu, 08 Jan 2015 00:08:21 -0800
- In-reply-to: <20150108064816.GA17816@lorien.comfychair.org>
- List-help: <mailto:zsh-workers-help@zsh.org>
- List-id: Zsh Workers List <zsh-workers.zsh.org>
- List-post: <mailto:zsh-workers@zsh.org>
- Mailing-list: contact zsh-workers-help@xxxxxxx; run by ezmlm
- References: <20141222203624.GA24855@tarsus.local2> <141227223029.ZM15959@torch.brasslantern.com> <141227234421.ZM16038@torch.brasslantern.com> <141228004101.ZM28486@torch.brasslantern.com> <20141229004957.GA1737@tarsus.local2> <141228200142.ZM22840@torch.brasslantern.com> <20150107220345.GE1714@tarsus.local2> <CAH+w=7Y3r3UeFPdHjPsS9arrWWjss2Bco1i0hNsn6fb8sfv7Xw@mail.gmail.com> <20150108064816.GA17816@lorien.comfychair.org>
On Jan 7, 10:48pm, Danek Duvall wrote:
} Subject: Re: [PATCH] Re: Insecure tempfile creation
}
} On Wed, Jan 07, 2015 at 10:22:20PM -0800, Bart Schaefer wrote:
}
} > On Wed, Jan 7, 2015 at 2:03 PM, Daniel Shahaf <d.s@xxxxxxxxxxxxxxxxxx> wrote:
} > > Coming back to this, it has occurred to me that
} > >
} > > mv -f =(:) ${TMPPREFIX:-/tmp/zsh}foo$$
} > >
} >
} > Hmm. Yup, we need "ln -Fh" instead of "mv -f". Are the -F and -h
} > options of "ln" fairly standard?
}
} Neither exists on Solaris ln. GNU coreutils ln doesn't seem to have -h,
} either. And -F just seems like a bad idea, supported or not.
-F on MacOS (where I was reading the manual) is like -f in coreutils,
not like -F in coreutils (sigh). And -h is --no-dereference.
} What about mktemp?
That doesn't help; it's exactly the same as =(:) for this purpose. The
"mv" trick above is used where we need to create a file with a specific
name -- if we did not need a specific name, we could just use the name
created by =(:) directly.
Fortunately, we have the zsh/files module which provides a buitin "ln"
with well-defined semantics. Hopefully that's good enough.
Messages sorted by:
Reverse Date,
Date,
Thread,
Author