Skip to content

docs: drop the /tmp pid fallback; document .hypatia-ignore consumers - #1076

Open
hyperpolymath wants to merge 3 commits into
mainfrom
fix/launcher-xdg-ladder-and-exemption-docs
Open

hyperpolymath wants to merge 3 commits into
mainfrom
fix/launcher-xdg-ladder-and-exemption-docs

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Part C of the launcher /tmp cure (origin: a Hypatia content_patterns/hardcoded_tmp alert on launch-scaffolder#46).

launcher-standard — deed + adoc in lock-step

  • :pid-file-pattern → ${XDG_RUNTIME_DIR:-${XDG_STATE_HOME:-$HOME/.local/state}}/launch-scaffolder/{app-name}/server.pid
  • :log-file-pattern → ${XDG_STATE_HOME:-$HOME/.local/state}/launch-scaffolder/{app-name}/server.log

The runtime hunk is copied verbatim from launch-scaffolder main's baked standards/launcher-standard_praxis.deed (#54/#58/#62). Its generator already emits this ladder. The old ${TMPDIR:-/tmp} last resort was the CWE-377 target named by the standard's own rationale: a predictable name in a world-writable dir lets another user choose which PID stop kills. The adoc template, the --disinteg list, the debugging checklist, logging and Security sections all move with it.

No :standard-version bump, deliberately. launch-scaffolder already bakes this ladder at 0.4.0. A bump would desync the two copies and make check-launcher-standard-currency.sh fail every 0.4.0 claim. Launchers on the old ladder are now non-conforming by design; the A8 re-mint sweep reaches them.

Out of scope, noted: the baked copy has also grown platforms, lifecycle-phases and metadata-block.encoding clauses that this canonical file lacks. That is a separate reconciliation.

QUICKSTART

It taught PID_FILE="/tmp/myapp-server.pid" and friends in seven places, contradicting the standard in the same directory. This is the likely seed of the ~17 shipped /tmp launchers. All are replaced; the hardcoded_tmp regex ["'/]tmp/ now matches nothing in the file.

EXEMPTION-MECHANISMS

The document said .hypatia-ignore is "never read by anything", and told reviewers to reject it. It also said Hypatia "ignores comments". Both are false. The new Layer 2a covers:

  • the two consumers and how each matches (scanner: substring fragment; governance gate: whole-line exact path);
  • why the gate is deliberately the stricter one;
  • the emitted-module trap (content_patterns/…, not cicd_rules/…);
  • the suppression ladder.

The anti-pattern list now rejects directory, wildcard and wrong-module lines, and invented pragmas, instead of the file itself.

Why the gate matcher is not loosened to substring matching: gate ⊂ scanner, so the mismatch can only false-block, never false-pass. Containment would let a …:src/ line absorb every future banned file. A census of 266 local .hypatia-ignore files found 0 directory, wildcard or /-terminated lines for the two gate rules, so no repo is currently hit by the divergence.

⚠ Inline hypatia: allow on content-pattern rules needs hyperpolymath/hypatia#881 (armed).

Added after review (e0c96f7, a530b71)

QUICKSTART Step 1 copies comprehensive-launcher-template.sh, which still wrote pid/log to /tmp and created no directory — so the doc and the file it hands the reader disagreed, and the XDG ladder would fail on the first nohup … > "$LOG_FILE". The comprehensive, dustfile and e-grade templates now use the ladder and mkdir -p -m 0700 the leaf directory before first write (SC2174 is intended: only the per-app leaf needs 0700). README checklist and a soft-attach.sh usage example no longer teach /tmp. After this, the only /tmp mentions under docs/UX-standards and launcher/ are launcher-standard.adoc’s explicit prohibitions.

🤖 Generated with Claude Code

https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK

launcher-standard (deed + adoc, lock-step): the pid ladder becomes
${XDG_RUNTIME_DIR:-${XDG_STATE_HOME:-$HOME/.local/state}}/launch-scaffolder/{app-name}/server.pid
and logs move under launch-scaffolder/{app-name}/, matching the generator
on launch-scaffolder main (#54/#58/#62). The old ${TMPDIR:-/tmp} last
resort was the CWE-377 target the standard's own rationale names. No
:standard-version bump, deliberately: launch-scaffolder already bakes
THIS ladder at 0.4.0, so a bump here would desync the two copies and make
scripts/check-launcher-standard-currency.sh fail every 0.4.0 claim. Shipped
launchers on the old /tmp ladder are now non-conforming -- that is the
point; the A8 re-mint sweep reaches them.

QUICKSTART taught PID_FILE="/tmp/myapp-server.pid" in seven places,
contradicting the standard in the same directory -- the likely seed of
the ~17 shipped /tmp launchers.

EXEMPTION-MECHANISMS said .hypatia-ignore is "never read by anything"
and told reviewers to reject it. It has two live consumers (the Hypatia
scanner: substring fragments; the governance gate: whole-line exact
paths). New Layer 2a documents both and the emitted-module trap.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
@hyperpolymath
hyperpolymath enabled auto-merge (squash) September 30, 2026 10:15
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 40 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: b169945e-807a-490a-bd8c-92a39f576e2f

📥 Commits

Reviewing files that changed from the base of the PR and between bd9313a and a530b71.

📒 Files selected for processing (9)
  • docs/EXEMPTION-MECHANISMS.adoc
  • docs/UX-standards/QUICKSTART.adoc
  • docs/UX-standards/README.adoc
  • docs/UX-standards/comprehensive-launcher-template.sh
  • docs/UX-standards/dustfile-template.sh
  • docs/UX-standards/e-grade-launcher-template.sh
  • docs/UX-standards/launcher-standard.adoc
  • launcher/launcher-standard_praxis.deed
  • launcher/soft-attach.sh

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

hyperpolymath and others added 2 commits September 30, 2026 11:22
QUICKSTART Step 1 copies comprehensive-launcher-template.sh and Step 2
edits its CONFIGURATION block, but the template still carried
/tmp/<app>-server.{pid,log} and created no directory. A reader following
the doc verbatim would either keep the CWE-377 path or, after switching
to the XDG ladder, fail on the first `nohup ... > "$LOG_FILE"`.

Both templates (the dustfile reads the launcher's pid/log, so they must
agree) now use the standard's ladder and `mkdir -p -m 0700` the leaf
directories immediately before the first write.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
README's checklist still recommended "/tmp/app-name.log", the e-grade
template logged to /tmp, and soft-attach.sh's usage example passed a
/tmp log. Only launcher-standard.adoc's explicit prohibitions of /tmp
remain after this.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
hyperpolymath added a commit to hyperpolymath/launch-scaffolder that referenced this pull request Sep 30, 2026
…#63)

`docs/compliance-audit-2026-04-10.adoc` is a **frozen snapshot** ("do
not update it"). Its aerie row calls `/tmp/aerie.pid` a
*"standard-compliant predictable name"*, which was only true of the
2026-04-10 standard.

This PR leaves every frozen row untouched. It adds a dated **erratum**
under the banner saying that, under the current
`launcher-standard_praxis.deed` (#62; canonical copy in
hyperpolymath/standards#1076), a `/tmp` or `$TMPDIR` pid file is
non-compliant (CWE-377). The row therefore stops being citable as
precedent.

Part C3 of the launcher `/tmp` cure.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant