diff --git a/1-formats/sub-specs/inline-annotations/extractor/batch-extract.sh b/1-formats/sub-specs/inline-annotations/extractor/batch-extract.sh index d545c0b40..402e5a45d 100755 --- a/1-formats/sub-specs/inline-annotations/extractor/batch-extract.sh +++ b/1-formats/sub-specs/inline-annotations/extractor/batch-extract.sh @@ -8,7 +8,7 @@ set -eu ROOT="${1:-.}" -OUT_DIR="${2:-/tmp/inline-annotations-output}" +OUT_DIR="${2:-$(mktemp -d "${TMPDIR:-/tmp}/inline-annotations-output.XXXXXX")}" EXTRACTOR="$(dirname "$0")/target/release/inline-annotations" [ -x "$EXTRACTOR" ] || EXTRACTOR="$(dirname "$0")/target/debug/inline-annotations" [ -x "$EXTRACTOR" ] || { echo "inline-annotations binary not found — run cargo build first"; exit 1; } diff --git a/rhodium-standard-repositories/ux-test-harness/run-ux-test.sh b/rhodium-standard-repositories/ux-test-harness/run-ux-test.sh index 5ae140363..57e2ad9c2 100755 --- a/rhodium-standard-repositories/ux-test-harness/run-ux-test.sh +++ b/rhodium-standard-repositories/ux-test-harness/run-ux-test.sh @@ -9,7 +9,6 @@ set -uo pipefail REPO_DIR="/repo" -REPORT_FILE="/tmp/ux-test-report.json" OS_ID="$(cat /etc/os-release 2>/dev/null | grep '^ID=' | cut -d= -f2 | tr -d '"')" OS_VERSION="$(cat /etc/os-release 2>/dev/null | grep '^VERSION_ID=' | cut -d= -f2 | tr -d '"')" ARCH="$(uname -m)" diff --git a/rhodium-standard-repositories/ux-test-harness/test-repo.sh b/rhodium-standard-repositories/ux-test-harness/test-repo.sh index 18f490ed9..b7779dc92 100755 --- a/rhodium-standard-repositories/ux-test-harness/test-repo.sh +++ b/rhodium-standard-repositories/ux-test-harness/test-repo.sh @@ -5,7 +5,8 @@ # Usage: ./test-repo.sh /path/to/repo [platform...] # Platforms: fedora, ubuntu, alpine, debian (default: all) # -# Output: JSON reports in /tmp/ux-test-results// +# Output: JSON reports in a per-run temp directory under $TMPDIR (the +# exact path is printed to stdout — see "Results:" below). set -euo pipefail @@ -13,7 +14,7 @@ REPO="${1:?Usage: $0 /path/to/repo [fedora|ubuntu|alpine|debian]}" REPO="$(realpath "$REPO")" REPO_NAME="$(basename "$REPO")" HARNESS_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" -RESULTS_DIR="/tmp/ux-test-results/$REPO_NAME" +RESULTS_DIR="$(mktemp -d "${TMPDIR:-/tmp}/ux-test-results.${REPO_NAME}.XXXXXX")" shift || true PLATFORMS=("${@:-fedora ubuntu alpine debian}") diff --git a/scripts/check-lockfile-drift.sh b/scripts/check-lockfile-drift.sh index bd01e5d19..babfa2495 100755 --- a/scripts/check-lockfile-drift.sh +++ b/scripts/check-lockfile-drift.sh @@ -66,6 +66,10 @@ WFDIR="$REPO_DIR/.github/workflows" drift=0 checked=0 +want_tmp="$(mktemp)" +have_tmp="$(mktemp)" +trap 'rm -f "$want_tmp" "$have_tmp"' EXIT + for wf in "$WFDIR"/*.yml "$WFDIR"/*.yaml; do [ -f "$wf" ] || continue base="$(basename "$wf")" @@ -83,20 +87,20 @@ for wf in "$WFDIR"/*.yml "$WFDIR"/*.yaml; do | sed -E 's/uses:[[:space:]]*//' \ | grep -v '/\.github/workflows/' \ | sed -E 's#^([^/]+/[^/@]+)(/[^@]*)?@#\1@#' \ - | sort -u > /tmp/_drift_want.$$ || true + | sort -u > "$want_tmp" || true - [ -s /tmp/_drift_want.$$ ] || { rm -f /tmp/_drift_want.$$; continue; } + [ -s "$want_tmp" ] || continue # Versions the lockfile records for THIS workflow. awk -v key=" '.github/workflows/$base':" ' $0 == key { on = 1; next } on && /^ - / { gsub(/^ - .|.$/, ""); print; next } on && NF && $0 !~ /^ / { exit } - ' "$LOCK" | sort -u > /tmp/_drift_have.$$ || true + ' "$LOCK" | sort -u > "$have_tmp" || true while read -r want; do [ -n "$want" ] || continue - grep -qxF "$want" /tmp/_drift_have.$$ && continue + grep -qxF "$want" "$have_tmp" && continue name="${want%@*}" ref="${want#*@}" @@ -104,7 +108,7 @@ for wf in "$WFDIR"/*.yml "$WFDIR"/*.yaml; do # Only DRIFT if the lockfile knows this action at a *different* version. # Absent entirely is mode 2/3, or a verified-creator action that # legitimately needs no entry (e.g. Swatinem/rust-cache) — not drift. - have="$(grep -m1 -F "$name@" /tmp/_drift_have.$$)" || continue + have="$(grep -m1 -F "$name@" "$have_tmp")" || continue # A workflow may pin by 40-char SHA while the lockfile records a TAG. # That is the same action in two notations, NOT drift. The lockfile @@ -121,9 +125,7 @@ for wf in "$WFDIR"/*.yml "$WFDIR"/*.yaml; do printf '%s\t%s\t%s\t%s\n' "$REPO_SLUG" "$base" "$want" "$have" drift=$((drift + 1)) - done < /tmp/_drift_want.$$ - - rm -f /tmp/_drift_want.$$ /tmp/_drift_have.$$ + done < "$want_tmp" done if [ "$drift" -gt 0 ]; then diff --git a/scripts/registry-readiness.sh b/scripts/registry-readiness.sh index 75d63946d..13ca64e72 100644 --- a/scripts/registry-readiness.sh +++ b/scripts/registry-readiness.sh @@ -116,9 +116,10 @@ fi say "== 4. Tests (authoritative — paste real result) ==" if [ -f Project.toml ] && command -v julia >/dev/null 2>&1; then - if timeout 560 julia --project=. -e 'using Pkg; Pkg.test()' 2>&1 | tee /tmp/rr_test.$$ | tail -3; then - grep -q "Testing .* tests passed" /tmp/rr_test.$$ && ok "Pkg.test() passed" || flag "Pkg.test() did NOT pass — inspect /tmp/rr_test.$$" - else flag "Pkg.test() errored — inspect /tmp/rr_test.$$"; fi + rr_log="$(mktemp)" + if timeout 560 julia --project=. -e 'using Pkg; Pkg.test()' 2>&1 | tee "$rr_log" | tail -3; then + grep -q "Testing .* tests passed" "$rr_log" && ok "Pkg.test() passed" || flag "Pkg.test() did NOT pass — inspect $rr_log" + else flag "Pkg.test() errored — inspect $rr_log"; fi else warn "skipped tests (no Project.toml or julia)"; fi say "${GRN}== registry-readiness pass complete — review, then commit on this branch ==${NC}"