Re: Use mkstemp() instead of tempnam() in rfc1867.c?
| From: | Sascha Schumann | Date: | Mon, 21 Aug 2000 17:49:03 +0000 |
| Subject: | Re: Use mkstemp() instead of tempnam() in rfc1867.c? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-30083@lists.php.net to get a copy of this message | ||
On Mon, 21 Aug 2000, Stanislav Malyshev wrote:
> JS>> Right now, main/rfc1867.c uses tempnam() for creating the temporary file
> JS>> to store uploads in. Simply wondering if anyone thinks it would bew
> JS>> worth rewriting this section to use mkstemp instead?
>
> That's hard to do, for following reasons:
> 1. mkstemp opens file, which doesn't fit current code flow
That is no argument. If a specific code has security
problems, you don't complain about how hard it is to rewrite
it; you simply do it.
(This also applies to the pieces of code which use
strlcat/strlcpy. These functions are for fixing broken/legacy
code quickly.)
> 2. win32 doesn't have mkstemp, and we cannot easily define it out because
> of 1. I'm not even sure all Unix platforms have mkstemp.
Well, so write a mkstemp replacement which uses tempnam and
opens the file. This can be easily implemented for Win32 and
other platforms which lack a native mkstemp.
This is not to say that it must be done. But I want to
emphasize that it is possible and feasible.
- Sascha