220 5325 <CAFk2RUbd4rMXmDgegBKZum_+xN1JPKmrxFX7fW91UfO_Fd9PQA@mail.gmail.com> article
Path: news.gmane.org!not-for-mail
From: Ville Voutilainen <ville.voutilainen@gmail.com>
Newsgroups: gmane.comp.lang.c++.isocpp.proposals
Subject: Re: Remove filesystem unique_path
Date: Sun, 7 Jul 2013 14:09:41 +0300
Lines: 88
Approved: news@gmane.org
Message-ID: <CAFk2RUbd4rMXmDgegBKZum_+xN1JPKmrxFX7fW91UfO_Fd9PQA@mail.gmail.com>
References: <4b95e9b9-d5cc-4314-bd32-1e09fe35ed9d@isocpp.org>
Reply-To: std-proposals@isocpp.org
NNTP-Posting-Host: plane.gmane.org
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary=047d7b6da616f243fe04e0e9f600
X-Trace: ger.gmane.org 1373195385 28775 80.91.229.3 (7 Jul 2013 11:09:45 GMT)
X-Complaints-To: usenet@ger.gmane.org
NNTP-Posting-Date: Sun, 7 Jul 2013 11:09:45 +0000 (UTC)
To: std-proposals@isocpp.org
Original-X-From: std-proposals+bncBC5JHI7A7ALRB5UY4WHAKGQEOZ7B7DY@isocpp.org Sun Jul 07 13:09:47 2013
Return-path: <std-proposals+bncBC5JHI7A7ALRB5UY4WHAKGQEOZ7B7DY@isocpp.org>
Envelope-to: gclcip-std-proposals@m.gmane.org
Original-Received: from mail-gh0-f199.google.com ([209.85.160.199])
	by plane.gmane.org with esmtp (Exim 4.69)
	(envelope-from <std-proposals+bncBC5JHI7A7ALRB5UY4WHAKGQEOZ7B7DY@isocpp.org>)
	id 1Uvmqd-0000K0-IK
	for gclcip-std-proposals@m.gmane.org; Sun, 07 Jul 2013 13:09:43 +0200
Original-Received: by mail-gh0-f199.google.com with SMTP id g14sf4192839ghb.6
        for <gclcip-std-proposals@m.gmane.org>; Sun, 07 Jul 2013 04:09:42 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=gmail.com; s=20120113;
        h=x-beenthere:mime-version:in-reply-to:references:date:message-id
         :subject:from:to:x-original-sender:x-original-authentication-results
         :reply-to:precedence:mailing-list:list-id:x-google-group-id
         :list-post:list-help:list-archive:list-subscribe:list-unsubscribe
         :content-type;
        bh=u8RYVFfChpEFx6cWV0GAR0lJzK08mRXgdZ5SwQLWi2k=;
        b=fnltJvvHtNtV8HQVioFaoorYWshY2OndwedTjdTSx1mtzxQiufNxH65+nXbtXMX6hN
         M88cr6LV40COmmLWBq0YBLTf/SbNXexezxSHpxtQZLLgRzYhf3+kdS79kE3/3P7XqG6b
         kdm0kVJWvuqp/AXnd31ABm5A4KDoM2ec37rJ844MAzxkVgUsN7RdoA2zvigYAgBaBb6n
         gstU/LHnaBWVLZyEPUNEB2Ur5DFJevH3un7xdzapTC2DCytNpwAQwM4f98O0HjufY6MC
         pHpM1E7XWukwBU2qdjDYt48SNy3Mi1pJPWHvWhsypDcEPKFRscIbDZwhpzCS6QHHQ7TX
         dWQQ==
X-Received: by 10.224.55.200 with SMTP id v8mr20193067qag.7.1373195382457;
        Sun, 07 Jul 2013 04:09:42 -0700 (PDT)
X-BeenThere: std-proposals@isocpp.org
Original-Received: by 10.49.48.115 with SMTP id k19ls1497637qen.5.gmail; Sun, 07 Jul
 2013 04:09:42 -0700 (PDT)
X-Received: by 10.229.10.65 with SMTP id o1mr2762645qco.87.1373195382032;
        Sun, 07 Jul 2013 04:09:42 -0700 (PDT)
Original-Received: from mail-qa0-x22f.google.com (mail-qa0-x22f.google.com [2607:f8b0:400d:c00::22f])
        by mx.google.com with ESMTPS id r10si3557150qai.77.2013.07.07.04.09.42
        for <std-proposals@isocpp.org>
        (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128);
        Sun, 07 Jul 2013 04:09:42 -0700 (PDT)
Received-SPF: pass (google.com: domain of ville.voutilainen@gmail.com designates 2607:f8b0:400d:c00::22f as permitted sender) client-ip=2607:f8b0:400d:c00::22f;
Original-Received: by mail-qa0-f47.google.com with SMTP id i13so5243433qae.6
        for <std-proposals@isocpp.org>; Sun, 07 Jul 2013 04:09:42 -0700 (PDT)
X-Received: by 10.49.95.97 with SMTP id dj1mr11477266qeb.46.1373195381914;
 Sun, 07 Jul 2013 04:09:41 -0700 (PDT)
Original-Received: by 10.224.52.71 with HTTP; Sun, 7 Jul 2013 04:09:41 -0700 (PDT)
In-Reply-To: <4b95e9b9-d5cc-4314-bd32-1e09fe35ed9d@isocpp.org>
X-Original-Sender: ville.voutilainen@gmail.com
X-Original-Authentication-Results: mx.google.com;       spf=pass (google.com:
 domain of ville.voutilainen@gmail.com designates 2607:f8b0:400d:c00::22f as
 permitted sender) smtp.mail=ville.voutilainen@gmail.com;       dkim=pass header.i=@gmail.com
Precedence: list
Mailing-list: list std-proposals@isocpp.org; contact std-proposals+owners@isocpp.org
List-ID: <std-proposals.isocpp.org>
X-Google-Group-Id: 399137483710
List-Post: <http://groups.google.com/a/isocpp.org/group/std-proposals/post>, <mailto:std-proposals@isocpp.org>
List-Help: <http://support.google.com/a/isocpp.org/bin/topic.py?topic=25838>, <mailto:std-proposals+help@isocpp.org>
List-Archive: <http://groups.google.com/a/isocpp.org/group/std-proposals/>
List-Subscribe: <http://groups.google.com/a/isocpp.org/group/std-proposals/subscribe>,
 <mailto:std-proposals+subscribe@isocpp.org>
List-Unsubscribe: <http://groups.google.com/a/isocpp.org/group/std-proposals/subscribe>,
 <mailto:googlegroups-manage+399137483710+unsubscribe@googlegroups.com>
Xref: news.gmane.org gmane.comp.lang.c++.isocpp.proposals:5325
Archived-At: <http://permalink.gmane.org/gmane.comp.lang.c++.isocpp.proposals/5325>

--047d7b6da616f243fe04e0e9f600
Content-Type: text/plain; charset=ISO-8859-1

On 7 July 2013 13:59, <magfr@lysator.liu.se> wrote:

> I was surprised when I looked at the file system proposal and found
> unique_path.
>
> unique_path is similar to the POSIX tempnam[1] function that was marked as
> obsolecent in POSIX 2008 and tmpfile, mkdtemp and mkstemp recommended in
> it's place. Why incorporate the mistakes from posix in C++?
>
> The problem with unique_path is that there is a window of opportunity
> between the check that the path name is unique and the time when it is used.
> That window can be used by malware -- and in the case of tempnam it have
> been used by malware.
>
> I thus propose that 15.38 is removed.
>
>
This is a known issue, but the current plan is to include unique_path and
document the race possibility.
That means that users need to be careful where and when to use unique_path.
The function itself
is still useful, but it can't be used under the circumstances under which
tmpnam() is unsafe.

Having a mkstemp/mkdtemp equivalent is something that should probably be
handled in subsequent
revisions of the filesystem library.

-- 

--- 
You received this message because you are subscribed to the Google Groups "ISO C++ Standard - Future Proposals" group.
To unsubscribe from this group and stop receiving emails from it, send an email to std-proposals+unsubscribe@isocpp.org.
To post to this group, send email to std-proposals@isocpp.org.
Visit this group at http://groups.google.com/a/isocpp.org/group/std-proposals/.



--047d7b6da616f243fe04e0e9f600
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><br><div class=3D"gmail=
_quote">On 7 July 2013 13:59,  <span dir=3D"ltr">&lt;<a href=3D"mailto:magf=
r@lysator.liu.se" target=3D"_blank">magfr@lysator.liu.se</a>&gt;</span> wro=
te:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-=
left:1px #ccc solid;padding-left:1ex">
I was surprised when I looked at the file system proposal and found unique_=
path.<br><br>unique_path is similar to the POSIX tempnam[1] function that w=
as marked as obsolecent in POSIX 2008 and tmpfile, mkdtemp and mkstemp reco=
mmended in it&#39;s place. Why incorporate the mistakes from posix in C++?<=
br>
<br>The problem with unique_path is that there is a window of opportunity b=
etween the check that the path name is unique and the time when it is used.=
<br>That window can be used by malware -- and in the case of tempnam it hav=
e been used by malware.<br>
<br>I thus propose that 15.38 is removed.<span class=3D"HOEnZb"><font color=
=3D"#888888"><br><br></font></span></blockquote><div><br></div><div>This is=
 a known issue, but the current plan is to include unique_path and document=
 the race possibility.<br>
</div><div>That means that users need to be careful where and when to use u=
nique_path. The function itself<br>is still useful, but it can&#39;t be use=
d under the circumstances under which tmpnam() is unsafe.<br><br></div>
<div>Having a mkstemp/mkdtemp equivalent is something that should probably =
be handled in subsequent<br></div><div>revisions of the filesystem library.=
 <br></div></div><br></div></div>

<p></p>

-- <br />
&nbsp;<br />
--- <br />
You received this message because you are subscribed to the Google Groups &=
quot;ISO C++ Standard - Future Proposals&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to std-proposals+unsubscribe@isocpp.org.<br />
To post to this group, send email to std-proposals@isocpp.org.<br />
Visit this group at <a href=3D"http://groups.google.com/a/isocpp.org/group/=
std-proposals/">http://groups.google.com/a/isocpp.org/group/std-proposals/<=
/a>.<br />
&nbsp;<br />
&nbsp;<br />

--047d7b6da616f243fe04e0e9f600--

.
