Skip to content

fix(standard): the standard, not the generator, owns launcher runtime paths - #62

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/a9-standard-drives-runtime-paths
Sep 30, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/a9-standard-drives-runtime-paths

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Why

#54/#58 cured the /tmp pid/log defaults in template.rs, but standards/launcher-standard_praxis.deed:126,129 still mandated ${XDG_RUNTIME_DIR:-${TMPDIR:-/tmp}}/{app-name}-server.pid, and render() never read it. Generator and standard had drifted apart again, which is the same class of defect as #48, where the code sat under a comment claiming to follow the standard.

What

  • Standard. :pid-file-pattern and :log-file-pattern now carry the generator's XDG-only ladder, …/launch-scaffolder/{app-name}/server.{pid,log}, with the CWE-377 rationale.

  • Accessors. LauncherStandard::{pid,log}_file_pattern() refuses three cases with a hard error:

    • a missing key (never a silent fallback)
    • a pattern without {app-name}
    • a pattern naming /tmp or TMPDIR

    mint resolves the standard through an on-disk ladder, so a stale copy can reach render(). The refusal stops it minting a /tmp fallback.

  • Generator. template.rs now substitutes {app-name} into the standard's pattern. The *_is_default quoting is unchanged.

  • Audit scripts. docs/ruleset-audit-2026-04-10/*.sh accounted for six hardcoded_tmp alerts (#71–76). These files hand off between scripts: audit.sh writes report.jsonl, and the wave scripts read the repo lists. They now default to $SCRIPT_DIR, as RESULTS_FILE already did, and the env overrides still work. ⚠ This is a deliberate departure from the "mktemp -d + trap rm" instruction: that would delete audit.sh's own report on exit and leave the wave scripts with no inputs. ⚠ Running audit.sh in place now overwrites the committed report.jsonl record, where before it wrote to /tmp. Set REPORT_FILE to keep the record.

Evidence

  • cargo test --workspace: all green. cargo clippy --all-targets -D warnings: clean. cargo fmt --check: clean.
  • DEFAULT_PID_LINE/DEFAULT_LOG_LINE are byte-identical and green. The refactor changed where the value comes from, not what it is.
  • Mutant control. Corrupting only the deed's pid pattern turns template::tests::default_pid_and_log_paths_are_per_user_not_world_writable red, along with the four new accessor tests and the content pin. So the generator genuinely reads the standard.
  • A fresh mint of the fixture config is byte-identical to minted-2026-09-23_stapeln-launcher-deed.sh.
  • Audit scripts: bash -n passes. Shellcheck shows the same single pre-existing SC2034 before and after. ["'/]tmp/ finds 0 hits.

Not in this PR

  • :standard-version is deliberately not bumped. check-launcher-standard-currency.sh pins it estate-wide, so a bump would need a coordinated standards change.
  • The canonical standards/launcher/launcher-standard_praxis.deed still has the TMPDIR ladder, and it already lags this vendored copy (it has no platforms/lifecycle-phases/encoding clauses). That fix, together with its lockstep launcher-standard.adoc, goes in a standards PR.
  • Alerts #80/#81 on the frozen 09-22 fixture are intentional history. They get handled on the Hypatia side, through the training-corpus exemption.

🤖 Generated with Claude Code

https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK

… paths

#54/#58 moved the default pid/log paths out of /tmp in template.rs, but the
standard they claim to follow still said
${XDG_RUNTIME_DIR:-${TMPDIR:-/tmp}}/{app-name}-server.pid, and render()
never read it. Generator and standard had drifted again, under the same
kind of comment that hid the original defect (#48).

- standards/launcher-standard_praxis.deed: :pid-file-pattern and
  :log-file-pattern now carry the generator's XDG-only ladder under
  launch-scaffolder/{app-name}/, with the CWE-377 rationale.
- LauncherStandard::{pid,log}_file_pattern(): hard error on a missing key,
  a pattern without {app-name}, or one naming /tmp or TMPDIR (mint resolves
  the standard from an on-disk ladder, so a stale copy can reach render).
- template.rs substitutes {app-name} into the standard's pattern instead of
  its own format!. DEFAULT_PID_LINE/DEFAULT_LOG_LINE are byte-identical and
  green; a fresh mint is byte-identical to the committed 09-23 fixture.
  Mutant: corrupting only the deed's pattern turns the template test red.
- docs/ruleset-audit-2026-04-10: the six hardcoded_tmp alerts. These paths
  are a hand-off between audit.sh and the wave scripts, so they default to
  $SCRIPT_DIR (as RESULTS_FILE already did), not to a mktemp dir that would
  delete the report on exit. Env overrides unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 43edc8bb-6900-450a-94d5-fa3c9f77ab87

📥 Commits

Reviewing files that changed from the base of the PR and between f23acaf and 7bcc971.

📒 Files selected for processing (7)
  • crates/launcher-common/src/standard.rs
  • crates/launcher-common/src/template.rs
  • docs/ruleset-audit-2026-04-10/README.adoc
  • docs/ruleset-audit-2026-04-10/audit.sh
  • docs/ruleset-audit-2026-04-10/wave1-apply.sh
  • docs/ruleset-audit-2026-04-10/wave2-apply.sh
  • standards/launcher-standard_praxis.deed
 ___________________________________________________________
< Patience, young padawan. The bugs will reveal themselves. >
 -----------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 31ccfde into main Sep 30, 2026
18 of 22 checks passed
@hyperpolymath
hyperpolymath deleted the fix/a9-standard-drives-runtime-paths branch September 30, 2026 09:36
hyperpolymath added a commit that referenced this pull request Sep 30, 2026
…#63)

`docs/compliance-audit-2026-04-10.adoc` is a **frozen snapshot** ("do
not update it"). Its aerie row calls `/tmp/aerie.pid` a
*"standard-compliant predictable name"*, which was only true of the
2026-04-10 standard.

This PR leaves every frozen row untouched. It adds a dated **erratum**
under the banner saying that, under the current
`launcher-standard_praxis.deed` (#62; canonical copy in
hyperpolymath/standards#1076), a `/tmp` or `$TMPDIR` pid file is
non-compliant (CWE-377). The row therefore stops being citable as
precedent.

Part C3 of the launcher `/tmp` cure.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant