1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305
// Copyright 2017 The Chromium OS Authors. All rights reserved.
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE-BSD-3-Clause file.
// SPDX-License-Identifier: BSD-3-Clause
//! Struct for handling temporary files as well as any cleanup required.
//! The temporary files will be created with a name available as well as having
//! an exposed `fs::File` for reading/writing.
//! The file will be removed when the object goes out of scope.
//! # Examples
//! ```
//! use std::env::temp_dir;
//! use std::io::Write;
//! use std::path::{Path, PathBuf};
//! use vmm_sys_util::tempfile::TempFile;
//! let mut prefix = temp_dir();
//! prefix.push("tempfile");
//! let t = TempFile::new_with_prefix(prefix).unwrap();
//! let mut f = t.as_file();
//! f.write_all(b"hello world").unwrap();
//! f.sync_all().unwrap();
use std::env::temp_dir;
use std::ffi::OsStr;
use std::fs;
use std::fs::File;
use std::path::{Path, PathBuf};
use libc;
use crate::errno::{errno_result, Error, Result};
/// Wrapper for working with temporary files.
/// The file will be maintained for the lifetime of the `TempFile` object.
pub struct TempFile {
path: PathBuf,
file: Option<File>,
impl TempFile {
/// Creates the TempFile using a prefix.
/// # Arguments
/// `prefix`: The path and filename where to create the temporary file. Six
/// random alphanumeric characters will be added to the end of this to form
/// the filename.
pub fn new_with_prefix<P: AsRef<OsStr>>(prefix: P) -> Result<TempFile> {
use std::ffi::CString;
use std::os::unix::{ffi::OsStrExt, io::FromRawFd};
let mut os_fname = prefix.as_ref().to_os_string();
let raw_fname = match CString::new(os_fname.as_bytes()) {
Ok(c_string) => c_string.into_raw(),
Err(_) => return Err(Error::new(libc::EINVAL)),
// SAFETY: Safe because `raw_fname` originates from CString::into_raw, meaning
// it is a pointer to a nul-terminated sequence of characters.
let fd = unsafe { libc::mkstemp(raw_fname) };
if fd == -1 {
return errno_result();
// SAFETY: raw_fname originates from a call to CString::into_raw. The length
// of the string has not changed, as mkstemp returns a valid file name, and
// '\0' cannot be part of a valid filename.
let c_tempname = unsafe { CString::from_raw(raw_fname) };
let os_tempname = OsStr::from_bytes(c_tempname.as_bytes());
// SAFETY: Safe because we checked `fd != -1` above and we uniquely own the file
// descriptor. This `fd` will be freed etc when `File` and thus
// `TempFile` goes out of scope.
let file = unsafe { File::from_raw_fd(fd) };
Ok(TempFile {
path: PathBuf::from(os_tempname),
file: Some(file),
/// Creates the TempFile using a prefix.
/// # Arguments
/// `prefix`: The path and filename where to create the temporary file. Six
/// random alphanumeric characters will be added to the end of this to form
/// the filename.
pub fn new_with_prefix<P: AsRef<OsStr>>(prefix: P) -> Result<TempFile> {
use crate::rand::rand_alphanumerics;
use std::fs::OpenOptions;
let file_path_str = format!(
let file_path_buf = PathBuf::from(&file_path_str);
let file = OpenOptions::new()
Ok(TempFile {
path: file_path_buf,
file: Some(file),
/// Creates the TempFile inside a specific location.
/// # Arguments
/// `path`: The path where to create a temporary file with a filename formed from
/// six random alphanumeric characters.
pub fn new_in(path: &Path) -> Result<Self> {
let mut path_buf = path.canonicalize().unwrap();
// This `push` adds a trailing slash ("/whatever/path" -> "/whatever/path/").
// This is safe for paths with an already existing trailing slash.
let temp_file = TempFile::new_with_prefix(path_buf.as_path())?;
/// Creates the TempFile.
/// Creates a temporary file inside `$TMPDIR` if set, otherwise inside `/tmp`.
/// The filename will consist of six random alphanumeric characters.
pub fn new() -> Result<Self> {
let in_tmp_dir = temp_dir();
let temp_file = TempFile::new_in(in_tmp_dir.as_path())?;
/// Removes the temporary file.
/// Calling this is optional as dropping a `TempFile` object will also
/// remove the file. Calling remove explicitly allows for better error
/// handling.
pub fn remove(&mut self) -> Result<()> {
/// Returns the path to the file if the `TempFile` object that is wrapping the file
/// is still in scope.
/// If we remove the file by explicitly calling [`remove`](#method.remove),
/// `as_path()` can still be used to return the path to that file (even though that
/// path does not point at an existing entity anymore).
/// Calling `as_path()` after `remove()` is useful, for example, when you need a
/// random path string, but don't want an actual resource at that path.
pub fn as_path(&self) -> &Path {
/// Returns a reference to the File.
pub fn as_file(&self) -> &File {
// It's safe to unwrap because `file` can be `None` only after calling `into_file`
// which consumes this object.
/// Consumes the TempFile, returning the wrapped file.
/// This also removes the file from the system. The file descriptor remains opened and
/// it can be used until the returned file is dropped.
pub fn into_file(mut self) -> File {
impl Drop for TempFile {
fn drop(&mut self) {
let _ = self.remove();
mod tests {
use super::*;
use std::io::{Read, Write};
fn test_create_file_with_prefix() {
fn between(lower: u8, upper: u8, to_check: u8) -> bool {
(to_check >= lower) && (to_check <= upper)
let mut prefix = temp_dir();
let t = TempFile::new_with_prefix(&prefix).unwrap();
let path = t.as_path().to_owned();
// Check filename exists
// Check filename is in the correct location
// Check filename has random added
assert_eq!(path.file_name().unwrap().to_string_lossy().len(), 10);
// Check filename has only ascii letters / numbers
for n in path.file_name().unwrap().to_string_lossy().bytes() {
assert!(between(b'0', b'9', n) || between(b'a', b'z', n) || between(b'A', b'Z', n));
// Check we can write to the file
let mut f = t.as_file();
f.write_all(b"hello world").unwrap();
assert_eq!(f.metadata().unwrap().len(), 11);
fn test_create_file_new() {
let t = TempFile::new().unwrap();
let path = t.as_path().to_owned();
// Check filename is in the correct location
fn test_create_file_new_in() {
let t = TempFile::new_in(temp_dir().as_path()).unwrap();
let path = t.as_path().to_owned();
// Check filename exists
// Check filename is in the correct location
let t = TempFile::new_in(temp_dir().as_path()).unwrap();
let path = t.as_path().to_owned();
// Check filename is in the correct location
fn test_remove_file() {
let mut prefix = temp_dir();
let mut t = TempFile::new_with_prefix(prefix).unwrap();
let path = t.as_path().to_owned();
// Check removal.
// Calling `as_path()` after the file was removed is allowed.
let path_2 = t.as_path().to_owned();
assert_eq!(path, path_2);
// Check trying to remove a second time returns an error.
fn test_drop_file() {
let mut prefix = temp_dir();
let t = TempFile::new_with_prefix(prefix).unwrap();
let path = t.as_path().to_owned();
fn test_into_file() {
let mut prefix = temp_dir();
let text = b"hello world";
let temp_file = TempFile::new_with_prefix(prefix).unwrap();
let path = temp_file.as_path().to_owned();
fs::write(path, text).unwrap();
let mut file = temp_file.into_file();
let mut buf: Vec<u8> = Vec::new();
file.read_to_end(&mut buf).unwrap();
assert_eq!(buf, text);