Skip to content

fix(scripts): replace hardcoded /tmp paths with mktemp (#936) - #1072

Merged
hyperpolymath merged 2 commits into
mainfrom
fix/hypatia-tmp-mktemp
Sep 30, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
fix/hypatia-tmp-mktemp

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Closes #936.

Replaces the genuinely ephemeral hardcoded /tmp/… paths flagged by content_patterns/hardcoded_tmp with mktemp / mktemp -d:

File Change
scripts/check-lockfile-drift.sh per-loop /tmp/_drift_{want,have}.$$ → two mktemp files created once, trap … EXIT cleanup
scripts/registry-readiness.sh /tmp/rr_test.$$ → mktemp (no trap: the script tells the human to inspect the log afterwards)
ux-test-harness/run-ux-test.sh removed a dead REPORT_FILE=/tmp/… assignment that was never read
ux-test-harness/test-repo.sh RESULTS_DIR default → mktemp -d "${TMPDIR:-/tmp}/…XXXXXX"
inline-annotations/extractor/batch-extract.sh OUT_DIR default → mktemp -d, POSIX-safe; explicit $2 unchanged

Deliberately left, with reasons:

  • docs/UX-standards/*-launcher-template.sh, dustfile-template.sh: PID and log paths that a separate --stop/--status invocation must recompute. mktemp would break them.
  • scripts/sweep-classifiers/classify-*.sh: /tmp/drift-survey/ is a persistent content-addressed cache shared across a multi-script workflow, and it's already overridable.
  • Prose-only mentions in comments (launcher/soft-attach.sh, list-workflow-paths.sh).

For the finding count to reach zero, those remaining sites need either a rule precision fix or inline # hypatia: allow annotations with reasons. That will be a follow-up.

Verified locally: bash -n / sh -n clean on all 5 files. shellcheck is clean on 3 of them; the other 2 carry only pre-existing warnings on lines this PR doesn't touch.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65

Converts genuinely-ephemeral hardcoded /tmp/ scratch paths flagged by
Hypatia rule content_patterns/hardcoded_tmp to mktemp/mktemp -d, leaving
deterministic cross-invocation state paths and shared pipeline cache
dirs untouched (see PR/issue discussion for the full left/fixed split).

- scripts/check-lockfile-drift.sh: /tmp/_drift_want.$$ and
  /tmp/_drift_have.$$ (per-workflow loop scratch) -> mktemp once before
  the loop, with `trap ... EXIT` cleanup; removed the old per-iteration
  rm.
- scripts/registry-readiness.sh: /tmp/rr_test.$$ (julia Pkg.test()
  output capture) -> mktemp; no cleanup trap added since the script
  deliberately tells the human to inspect the log after it exits.
- rhodium-standard-repositories/ux-test-harness/run-ux-test.sh: removed
  a dead REPORT_FILE="/tmp/ux-test-report.json" assignment that was
  never read (the script's actual report goes to stdout via heredoc).
- rhodium-standard-repositories/ux-test-harness/test-repo.sh:
  RESULTS_DIR default -> mktemp -d under ${TMPDIR:-/tmp}; the resulting
  path is already surfaced to the user via existing "Results:"/"Full
  reports:" echo lines.
- 1-formats/sub-specs/inline-annotations/extractor/batch-extract.sh:
  OUT_DIR default -> mktemp -d under ${TMPDIR:-/tmp} using POSIX-safe
  lazy `${2:-$(...)}` expansion (script is #!/bin/sh); unchanged when
  an explicit $2 is passed.

Verified: bash -n / sh -n clean on all 5 files; shellcheck clean on
3 of 5 (check-lockfile-drift.sh, test-repo.sh, batch-extract.sh — the
POSIX one checked with -s sh). The other 2 files carry only
pre-existing warnings unrelated to these edits (registry-readiness.sh
SC2046/SC2015/SC2086 on unmodified lines, plus one SC2015 on the
touched Pkg.test() line that repeats the same A&&B||C idiom the file
already uses on three other untouched lines; run-ux-test.sh
SC2015/SC2016/SC2164/SC2001, all on lines untouched by this change).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 45 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: d5960471-122b-47d7-9b82-69a6c241499c

📥 Commits

Reviewing files that changed from the base of the PR and between 13baaa8 and 923d293.

📒 Files selected for processing (5)
  • 1-formats/sub-specs/inline-annotations/extractor/batch-extract.sh
  • rhodium-standard-repositories/ux-test-harness/run-ux-test.sh
  • rhodium-standard-repositories/ux-test-harness/test-repo.sh
  • scripts/check-lockfile-drift.sh
  • scripts/registry-readiness.sh
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath enabled auto-merge (squash) September 30, 2026 10:19
@hyperpolymath
hyperpolymath merged commit 51eeca7 into main Sep 30, 2026
45 of 48 checks passed
@hyperpolymath
hyperpolymath deleted the fix/hypatia-tmp-mktemp branch September 30, 2026 14:57
hyperpolymath added a commit that referenced this pull request Sep 30, 2026
…tale

#1072 and #1075 changed files under rhodium-standard-repositories/
without regenerating the registry, so `build-registry.sh --check` exits 1
on main. That reds "Registry + topology in sync" and both
build-registry-test.sh and build-scorecards-test.sh. And because the
test step fails, the "Lock-gate pin is not stale" step is skipped on
every PR. Output of `just registry`, one line.

Owner ruling D231: regenerate now; moving the registry off .a2ml stays
tracked in #1010/#479. Closes #1092.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
hyperpolymath added a commit that referenced this pull request Sep 30, 2026
…tale

#1072 and #1075 changed files under rhodium-standard-repositories/
without regenerating the registry, so `build-registry.sh --check` exits 1
on main. That reds "Registry + topology in sync" and both
build-registry-test.sh and build-scorecards-test.sh. And because the
test step fails, the "Lock-gate pin is not stale" step is skipped on
every PR. Output of `just registry`, one line.

Owner ruling D231: regenerate now; moving the registry off .a2ml stays
tracked in #1010/#479. Closes #1092.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
hyperpolymath added a commit that referenced this pull request Sep 30, 2026
…uuid-v7, map roots, canon 2.1.2, docstring calibration (#1088)

Restores `standards` main to green. The reds on main and on this PR hold
each other in a cycle, so every cure is in this one PR: under the
fully-green rule, no smaller PR can pass CI alone.

## What each commit fixes

1. **Lock-gate staging pin bump.** The `ref:` under "Checkout standards
for the lock gate" in `governance-reusable.yml` moves to `5f82b635`.
`scripts/check-lock-gate-pin-freshness.sh` returns rc=1 on main and rc=0
on this branch. Each tree's own copy of the script was run; running one
tree's copy against another tree reads the wrong workflow and passes
vacuously.
2. **Registry `source_hash` regeneration** (#1092). #1072 and #1075
changed files under the RSR spec home without regenerating
`.machine_readable/REGISTRY.a2ml`, so `build-registry.sh --check` fails.
That failure reds Self-tests, and the pin guard step never runs because
it comes after the failing suite. The change is one regenerated hash
line. Under D231 it is a regeneration only; migrating off the generated
file is a later piece of work.
3. **`uuid-v7.yml` hardening.** It adds `timeout-minutes: 10`, a
`concurrency` group, and a `push` trigger bounded to `main`. These are
the three unfiltered Hypatia Baseline findings on main:
missing_timeout_minutes, d_burn_double_trigger, and WH006.
4. **Delete the five unmapped root entries** (D241, cherry-picked and
signed from #1097). This cures the map-integrity red that woke on this
PR.
5. **Canon PATCH 2.1.1 → 2.1.2.** #1041 added a KNOWN-TENSIONS row under
`0-canon/constitution/` without the same-commit bump and sha256 rewrite
that `canon.lock` requires. Gate A is path-filtered, so main never ran
it and the drift stayed invisible until this PR woke the gate. This
commit bumps the version, sets released to 2026-09-30 and the tag to
`canon-v2.1.2`, rewrites the constitution hash to `be48496f…`, and adds
a header note. The spine's dogfood red was a stale hypatia compile
error, fixed upstream at 9d2e6de3. Re-running rsr-template-repo run
36475038466 turned it green.

6. **Fetch the docstring calibration commit by SHA** (#1099). #1073's
`docstring-scan-test.sh` calibrates against `1cc72cdc80c9`, PR #1034's
pre-squash head, which no clone of main can contain. Self Test on main
(run 36741131926) failed on this as well as the stale registry. I read
only the first failure, so my earlier claim that this PR cured every
main red was wrong. The test now fetches the commit by full SHA on a
miss, without `--depth` (which would make a complete clone shallow), and
still fails closed if the fetch fails. The branch was rebased onto main
74d2f66 (signed) so the test file is present.

Closes #1092
Closes #1094
Closes #1095
Closes #1099

## Local verification on 6192c92 (rebased on main 74d2f66)

| check | result |
|---|---|
| `bash scripts/run-shell-test-suite.sh` | 63 of 63 test files passed |
| `check-lock-gate-pin-freshness.sh origin/main` | PASS |
| `build-registry.sh --check` | clean |
| `check-canon-lockstep.sh --spine rsr-template-repo@8256a6e --base
origin/main` | GATE A PASSED (9 passed, 1 skipped: hypatia oracle not
local) |
| `check-standards-map.sh` | GATE D PASSED, 124 entries |
| **positive control:** one appended byte in `KNOWN-TENSIONS.adoc`,
`canon.lock` untouched | GATE A FAILED, naming `constitution` |
| docstring calibration: watched failing locally (object absent, 25
passed / 1 failed), then green after the fix | files=2, functions=13,
documented=0, skipped=3, coverage=0.00%; clone not shallow afterwards |

#1097 is superseded by commit 4. This PR lands under the fully-green
rule only when every check is green.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Hypatia content_patterns/hardcoded_tmp: /tmp paths without mktemp (30 instances)

1 participant