fix(standard): the standard, not the generator, owns launcher runtime paths - #62
Merged
Merged
Conversation
… paths #54/#58 moved the default pid/log paths out of /tmp in template.rs, but the standard they claim to follow still said ${XDG_RUNTIME_DIR:-${TMPDIR:-/tmp}}/{app-name}-server.pid, and render() never read it. Generator and standard had drifted again, under the same kind of comment that hid the original defect (#48). - standards/launcher-standard_praxis.deed: :pid-file-pattern and :log-file-pattern now carry the generator's XDG-only ladder under launch-scaffolder/{app-name}/, with the CWE-377 rationale. - LauncherStandard::{pid,log}_file_pattern(): hard error on a missing key, a pattern without {app-name}, or one naming /tmp or TMPDIR (mint resolves the standard from an on-disk ladder, so a stale copy can reach render). - template.rs substitutes {app-name} into the standard's pattern instead of its own format!. DEFAULT_PID_LINE/DEFAULT_LOG_LINE are byte-identical and green; a fresh mint is byte-identical to the committed 09-23 fixture. Mutant: corrupting only the deed's pattern turns the template test red. - docs/ruleset-audit-2026-04-10: the six hardcoded_tmp alerts. These paths are a hand-off between audit.sh and the wave scripts, so they default to $SCRIPT_DIR (as RESULTS_FILE already did), not to a mktemp dir that would delete the report on exit. Env overrides unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
Contributor
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (7)
✨ Finishing Touches📝 Generate docstrings
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
hyperpolymath
added a commit
that referenced
this pull request
Sep 30, 2026
…#63) `docs/compliance-audit-2026-04-10.adoc` is a **frozen snapshot** ("do not update it"). Its aerie row calls `/tmp/aerie.pid` a *"standard-compliant predictable name"*, which was only true of the 2026-04-10 standard. This PR leaves every frozen row untouched. It adds a dated **erratum** under the banner saying that, under the current `launcher-standard_praxis.deed` (#62; canonical copy in hyperpolymath/standards#1076), a `/tmp` or `$TMPDIR` pid file is non-compliant (CWE-377). The row therefore stops being citable as precedent. Part C3 of the launcher `/tmp` cure. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
#54/#58 cured the
/tmppid/log defaults intemplate.rs, butstandards/launcher-standard_praxis.deed:126,129still mandated${XDG_RUNTIME_DIR:-${TMPDIR:-/tmp}}/{app-name}-server.pid, andrender()never read it. Generator and standard had drifted apart again, which is the same class of defect as #48, where the code sat under a comment claiming to follow the standard.What
Standard.
:pid-file-patternand:log-file-patternnow carry the generator's XDG-only ladder,…/launch-scaffolder/{app-name}/server.{pid,log}, with the CWE-377 rationale.Accessors.
LauncherStandard::{pid,log}_file_pattern()refuses three cases with a hard error:{app-name}/tmporTMPDIRmintresolves the standard through an on-disk ladder, so a stale copy can reachrender(). The refusal stops it minting a/tmpfallback.Generator.
template.rsnow substitutes{app-name}into the standard's pattern. The*_is_defaultquoting is unchanged.Audit scripts.
docs/ruleset-audit-2026-04-10/*.shaccounted for sixhardcoded_tmpalerts (#71–76). These files hand off between scripts:audit.shwritesreport.jsonl, and the wave scripts read the repo lists. They now default to$SCRIPT_DIR, asRESULTS_FILEalready did, and the env overrides still work. ⚠ This is a deliberate departure from the "mktemp -d+trap rm" instruction: that would deleteaudit.sh's own report on exit and leave the wave scripts with no inputs. ⚠ Runningaudit.shin place now overwrites the committedreport.jsonlrecord, where before it wrote to/tmp. SetREPORT_FILEto keep the record.Evidence
cargo test --workspace: all green.cargo clippy --all-targets -D warnings: clean.cargo fmt --check: clean.DEFAULT_PID_LINE/DEFAULT_LOG_LINEare byte-identical and green. The refactor changed where the value comes from, not what it is.template::tests::default_pid_and_log_paths_are_per_user_not_world_writablered, along with the four new accessor tests and the content pin. So the generator genuinely reads the standard.mintof the fixture config is byte-identical tominted-2026-09-23_stapeln-launcher-deed.sh.bash -npasses. Shellcheck shows the same single pre-existing SC2034 before and after.["'/]tmp/finds 0 hits.Not in this PR
:standard-versionis deliberately not bumped.check-launcher-standard-currency.shpins it estate-wide, so a bump would need a coordinated standards change.standards/launcher/launcher-standard_praxis.deedstill has theTMPDIRladder, and it already lags this vendored copy (it has noplatforms/lifecycle-phases/encodingclauses). That fix, together with its locksteplauncher-standard.adoc, goes in a standards PR.🤖 Generated with Claude Code
https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK