https://github.com/python/cpython/commit/802f1457ed6088a1687907593f8cbfff102c6925 commit: 802f1457ed6088a1687907593f8cbfff102c6925 branch: main author: Mark Byrne <[email protected]> committer: vstinner <[email protected]> date: 2026-10-05T14:58:35Z summary:
gh-79459 tempfile: Raise a ValueError if the prefix or suffix contains a directory (#150477) Co-authored-by: Victor Stinner <[email protected]> Co-authored-by: blurb-it[bot] <43283697+blurb-it[bot]@users.noreply.github.com> files: A Misc/NEWS.d/next/Library/2026-10-05-13-57-08.gh-issue-79459.2RgBDL.rst M Lib/tempfile.py M Lib/test/test_tempfile.py diff --git a/Lib/tempfile.py b/Lib/tempfile.py index ad81c5d3417b4c..82c1ee353117e9 100644 --- a/Lib/tempfile.py +++ b/Lib/tempfile.py @@ -119,11 +119,15 @@ def _sanitize_params(prefix, suffix, dir): output_type = _infer_return_type(prefix, suffix, dir) if suffix is None: suffix = output_type() + if _os.path.dirname(suffix): + raise ValueError("suffix can't contain a directory component") if prefix is None: if output_type is str: prefix = template else: prefix = _os.fsencode(template) + if _os.path.dirname(prefix): + raise ValueError("prefix can't contain a directory component") if dir is None: if output_type is str: dir = gettempdir() diff --git a/Lib/test/test_tempfile.py b/Lib/test/test_tempfile.py index cd960ed99117b6..2f7b8798daa8c9 100644 --- a/Lib/test/test_tempfile.py +++ b/Lib/test/test_tempfile.py @@ -2154,5 +2154,46 @@ def test_cleanup_safe(self): # platforms, but don't forget to update the docs. self.assertTrue(tempfile._rmtree_use_dir_fd) + +class TestMisc(BaseTestCase): + def test_prefix_suffix_error(self): + tests = [ + f"dir{os.sep}name", + f"{os.sep}abs_name", + ] + if os.altsep is not None: + tests.extend(( + f"dir{os.altsep}name", + f"{os.altsep}abs_name", + )) + if support.MS_WINDOWS: + tests.append('C:name') + tests.extend(tuple(os.fsencode(path) for path in tests)) + + PREFIX_ERR = "prefix can't contain a directory component" + SUFFIX_ERR = "suffix can't contain a directory component" + for value in tests: + with self.subTest(value): + # test prefix + with self.assertRaisesRegex(ValueError, PREFIX_ERR): + tempfile.mkstemp(prefix=value) + with self.assertRaisesRegex(ValueError, PREFIX_ERR): + tempfile.mkdtemp(prefix=value) + with self.assertRaisesRegex(ValueError, PREFIX_ERR): + tempfile.TemporaryFile(prefix=value) + with self.assertRaisesRegex(ValueError, PREFIX_ERR): + tempfile.NamedTemporaryFile(prefix=value) + + # test suffix + with self.assertRaisesRegex(ValueError, SUFFIX_ERR): + tempfile.mkstemp(suffix=value) + with self.assertRaisesRegex(ValueError, SUFFIX_ERR): + tempfile.mkdtemp(suffix=value) + with self.assertRaisesRegex(ValueError, SUFFIX_ERR): + tempfile.TemporaryFile(suffix=value) + with self.assertRaisesRegex(ValueError, SUFFIX_ERR): + tempfile.NamedTemporaryFile(suffix=value) + + if __name__ == "__main__": unittest.main() diff --git a/Misc/NEWS.d/next/Library/2026-10-05-13-57-08.gh-issue-79459.2RgBDL.rst b/Misc/NEWS.d/next/Library/2026-10-05-13-57-08.gh-issue-79459.2RgBDL.rst new file mode 100644 index 00000000000000..2bbe77d6972e22 --- /dev/null +++ b/Misc/NEWS.d/next/Library/2026-10-05-13-57-08.gh-issue-79459.2RgBDL.rst @@ -0,0 +1,2 @@ +:mod:`tempfile` functions that take a ``prefix`` or ``suffix`` argument now raise a :exc:`ValueError` if they contain a directory component: +:func:`tempfile.mkstemp`, :func:`tempfile.mkdtemp`, :func:`tempfile.TemporaryFile`, :func:`tempfile.NamedTemporaryFile`. _______________________________________________ Python-checkins mailing list -- [email protected] To unsubscribe send an email to [email protected] https://mail.python.org/mailman3//lists/python-checkins.python.org Member address: [email protected]
