From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: by sourceware.org (Postfix, from userid 48) id ED042398B445; Tue, 15 Sep 2020 13:38:37 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org ED042398B445 From: "carlos at redhat dot com" To: glibc-bugs@sourceware.org Subject: [Bug libc/15813] Multiple issues in __gen_tempname Date: Tue, 15 Sep 2020 13:38:37 +0000 X-Bugzilla-Reason: CC X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: glibc X-Bugzilla-Component: libc X-Bugzilla-Version: unspecified X-Bugzilla-Keywords: X-Bugzilla-Severity: enhancement X-Bugzilla-Who: carlos at redhat dot com X-Bugzilla-Status: REOPENED X-Bugzilla-Resolution: X-Bugzilla-Priority: P2 X-Bugzilla-Assigned-To: adhemerval.zanella at linaro dot org X-Bugzilla-Target-Milestone: 2.31 X-Bugzilla-Flags: security? X-Bugzilla-Changed-Fields: Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: http://sourceware.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: glibc-bugs@sourceware.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Glibc-bugs mailing list List-Unsubscribe: , List-Archive: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 15 Sep 2020 13:38:38 -0000 https://sourceware.org/bugzilla/show_bug.cgi?id=3D15813 --- Comment #11 from Carlos O'Donell --- (In reply to Adhemerval Zanella from comment #10) > I meant the updated gnulib version from its repository, not the outdated > version glibc packs now. The gnulib version currently does not use neith= er > the process pid nor the clock for source of entropy, it uses either > getrandom or a simple linear congruential generator if getrandom fails. >=20 > I think using getentropy where available should make it more robust. These > interface contains inherent concurrent issues and applications should eit= her > use O_TMPFILE or at leat tmpfile. We should backport this to the release branch also since this is a regressi= on. --=20 You are receiving this mail because: You are on the CC list for the bug.=