Bug 765063 (GLUSTER-3331)

Summary: Do not use mktemp
Product: [Community] GlusterFS Reporter: Sachidananda Urs <sac>
Component: coreAssignee: Sachidananda Urs <sac>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: mainlineCC: amarts, gluster-bugs, saurabh
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Sachidananda Urs 2011-08-04 11:01:46 UTC
libglusterfs/src/compat.c:

char *
mkdtemp (char *tempstring)
{
    ...
        new_string = mktemp (tempstring);
        if (!new_string)
                goto out;
    ...
}

mktemp(3) is deprecated, use mkstemp(3).

Some implementations follow 4.3BSD and replace XXXXXX by the current process ID and a single letter, so that at most 26 different names can be returned.  Since on the one hand the names are easy to guess, and on the other hand there is a race between testing whether the name exists and opening the file, every use of mktemp() is a security risk. The race is avoided by mkstemp(3).

Comment 1 Anand Avati 2011-08-05 07:13:43 UTC
CHANGE: http://review.gluster.com/163 (Man page states:) merged in master by Anand Avati (avati)

Comment 2 Saurabh 2011-08-31 06:28:23 UTC
finding the code updated in the latest git sync.