Re: Re: PHP 4.0 Bug #5509 Updated: tempnam() is not safe

From: Date: Tue, 11 Jul 2000 08:09:26 +0000
Subject: Re: Re: PHP 4.0 Bug #5509 Updated: tempnam() is not safe
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-24167@lists.php.net to get a copy of this message
AH>> I'm not talking about security here, but about the safety of the AH>> temp-files of other processes and those of PHP itself. On servers with a AH>> bit of a load, a PHP-script page using tempnam could be requested twice AH>> in the time that it takes to generate a filename and open a AH>> filedescriptor using it, with a good chance of the one page overwriting Exactly. That's why you shouldn't use tempnam is such an environment. AH>> IMHO, it would be better to have an implementation of mkstemp() than one AH>> of tempnam(). mkstemp is doing much more than tempnam - it opens file. Since the straight-forward application of mkstemp is impossible (it is incompatible with PHP virtual directories, for example), integrating it takes significant amount of work. WHich nobody did yet. If you need it bad - code. If not - wait for somebody to do it. -- Stanislav Malyshev stas@zend.com +972-3-6139665

« previous php.dev (#24167) next »