From 30073a2e8ff9fdda3e2f4d68bbbe2bd78b427170 Mon Sep 17 00:00:00 2001 From: Alexandre Fayolle Date: Tue, 19 Mar 2013 11:20:08 +0100 Subject: [PATCH] [FIX] race condition in session directory creation try to create the directory and handle the possible exception instead of doing an unsafe 2 step check and creation. The issues related to the naming of the directory mentionned in the bug report are not handled. lp bug: https://launchpad.net/bugs/1157102 fixed bzr revid: alexandre.fayolle@camptocamp.com-20130319102008-omtaka8dtq9v7m1l --- addons/web/http.py | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/addons/web/http.py b/addons/web/http.py index e05d74e0873..d12cdfb13a1 100644 --- a/addons/web/http.py +++ b/addons/web/http.py @@ -20,6 +20,7 @@ import traceback import urlparse import uuid import xmlrpclib +import errno import babel.core import simplejson @@ -477,8 +478,15 @@ def session_path(): except Exception: username = "unknown" path = os.path.join(tempfile.gettempdir(), "oe-sessions-" + username) - if not os.path.exists(path): + try: os.mkdir(path, 0700) + except OSError as exc: + if exc.errno == errno.EEXIST: + # directory exists: ensure it has the correct permissions + # this will fail if the directory is not owned by the current user + os.chmod(path, 0700) + else: + raise return path class Root(object):