Re: Re: PHP 4.0 Bug #5509 Updated: tempnam() is not safe
| From: | Stanislav Malyshev | Date: | Tue, 11 Jul 2000 08:09:26 +0000 |
| Subject: | Re: Re: PHP 4.0 Bug #5509 Updated: tempnam() is not safe | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-24167@lists.php.net to get a copy of this message | ||
AH>> I'm not talking about security here, but about the safety of the
AH>> temp-files of other processes and those of PHP itself. On servers with a
AH>> bit of a load, a PHP-script page using tempnam could be requested twice
AH>> in the time that it takes to generate a filename and open a
AH>> filedescriptor using it, with a good chance of the one page overwriting
Exactly. That's why you shouldn't use tempnam is such an environment.
AH>> IMHO, it would be better to have an implementation of mkstemp() than one
AH>> of tempnam().
mkstemp is doing much more than tempnam - it opens file. Since the
straight-forward application of mkstemp is impossible (it is incompatible
with PHP virtual directories, for example), integrating it takes
significant amount of work. WHich nobody did yet. If you need it bad -
code. If not - wait for somebody to do it.
--
Stanislav Malyshev stas@zend.com
+972-3-6139665