[Python-Dev] Warn about mktemp once again?

Guido van Rossum guido at python.org
Tue Apr 29 01:01:09 CEST 2008


Have we documented the alternatives well enough? In most cases
NamedTemporaryFile will work, but sometimes you will have to create a
directory and pick names therein. Doing that so that it will always be
cleaned up properly is a bit of a trick, involving an isdir() check
and a shutil.rmtree() call.

On Sun, Apr 27, 2008 at 3:33 PM,  <skip at pobox.com> wrote:
> Back in r29829, Guido commented out the security hole warning for
>  tempfile.mktemp:
>
>     r29829 | gvanrossum | 2002-11-22 09:56:29 -0600 (Fri, 22 Nov 2002) | 3 lines
>
>     Comment out the warnings about mktemp().  These are too annoying, and
>     often unavoidable.
>
>  Any thought about whether this warning should be restored?  We're 5+ years
>  later.  Hopefully many uses of mktemp have been removed.  If we're not going
>  to restore the warning perhaps the commented code should just be deleted.
>
>  Skip
>
>  _______________________________________________
>  Python-Dev mailing list
>  Python-Dev at python.org
>  http://mail.python.org/mailman/listinfo/python-dev
>  Unsubscribe: http://mail.python.org/mailman/options/python-dev/guido%40python.org
>



-- 
--Guido van Rossum (home page: http://www.python.org/~guido/)


More information about the Python-Dev mailing list