From 24cd01c2548267ed4072f3ab80bad27a712505d1 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 15:55:42 +0100 Subject: [PATCH 1/3] fix(security): move repo-config.log off predictable /tmp path (CWE-377) configure-all-repos.sh wrote its audit log to the fixed path /tmp/repo-config.log. A predictable /tmp path lets another local user pre-create, symlink, or race the file before this script runs. LOG_FILE now resolves under the XDG state home (${XDG_STATE_HOME:-$HOME/.local/state}/personal-sysadmin/repo-config.log), with the parent directory created mode 0700 before the first write (split into `mkdir -p` + `chmod 0700` rather than `mkdir -p -m 0700`, to avoid a new shellcheck SC2174 warning; the leaf directory still ends up 0700). Every `$LOG_FILE` expansion is now double-quoted. This is a durable operator audit log (bookended "Starting configuration at ..." / "Configuration complete at ..." messages), not scratch, so it keeps a stable, re-findable path rather than moving to mktemp -d. /tmp/repos-to-configure.txt (lines using it are unchanged) is a durable, shared cache read by 9 sibling scripts in this directory and is deliberately NOT touched here -- converting it to ephemeral scratch would break all 9 consumers. Tracked separately: https://github.com/hyperpolymath/ambientops/issues/377 Verification: bash -n OK; shellcheck clean (matches baseline, only the pre-existing SC2162 on the `while read repo` loop); grep -nE "[\"'/]tmp/" shows exactly the 3 untouched repos-to-configure.txt lines (64, 65, 73), 0 hits on any touched line. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK --- .../scripts/github-admin/configure-all-repos.sh | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) diff --git a/personal-sysadmin/scripts/github-admin/configure-all-repos.sh b/personal-sysadmin/scripts/github-admin/configure-all-repos.sh index 7e9efbcb..68a64547 100755 --- a/personal-sysadmin/scripts/github-admin/configure-all-repos.sh +++ b/personal-sysadmin/scripts/github-admin/configure-all-repos.sh @@ -2,13 +2,15 @@ # Configure all hyperpolymath repos with standard settings OWNER="hyperpolymath" -LOG_FILE="/tmp/repo-config.log" +LOG_FILE="${XDG_STATE_HOME:-$HOME/.local/state}/personal-sysadmin/repo-config.log" +mkdir -p "$(dirname "$LOG_FILE")" +chmod 0700 "$(dirname "$LOG_FILE")" -echo "Starting configuration of all repos at $(date)" | tee $LOG_FILE +echo "Starting configuration of all repos at $(date)" | tee "$LOG_FILE" configure_repo() { local repo=$1 - echo "Configuring: $repo" | tee -a $LOG_FILE + echo "Configuring: $repo" | tee -a "$LOG_FILE" # 1. Update repository settings gh api "repos/$OWNER/$repo" -X PATCH \ @@ -54,7 +56,7 @@ PROTECTION gh api "repos/$OWNER/$repo/vulnerability-alerts" -X PUT --silent 2>/dev/null gh api "repos/$OWNER/$repo/automated-security-fixes" -X PUT --silent 2>/dev/null - echo " Done: $repo" | tee -a $LOG_FILE + echo " Done: $repo" | tee -a "$LOG_FILE" } # Get all repos @@ -71,5 +73,5 @@ while read repo; do done < /tmp/repos-to-configure.txt echo "" -echo "=== Configuration complete at $(date) ===" | tee -a $LOG_FILE -echo "Configured $count repos" | tee -a $LOG_FILE +echo "=== Configuration complete at $(date) ===" | tee -a "$LOG_FILE" +echo "Configured $count repos" | tee -a "$LOG_FILE" From 77932f6333a238b4a81c5ec73948dd7b34cce7bd Mon Sep 17 00:00:00 2001 From: "coderabbitai[bot]" <136622811+coderabbitai[bot]@users.noreply.github.com> Date: Wed, 30 Sep 2026 16:17:52 +0000 Subject: [PATCH 2/3] docs(github-admin): document configure_repo behavior, arguments, and globals --- personal-sysadmin/scripts/github-admin/configure-all-repos.sh | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/personal-sysadmin/scripts/github-admin/configure-all-repos.sh b/personal-sysadmin/scripts/github-admin/configure-all-repos.sh index 68a64547..bf26d2f4 100755 --- a/personal-sysadmin/scripts/github-admin/configure-all-repos.sh +++ b/personal-sysadmin/scripts/github-admin/configure-all-repos.sh @@ -8,6 +8,10 @@ chmod 0700 "$(dirname "$LOG_FILE")" echo "Starting configuration of all repos at $(date)" | tee "$LOG_FILE" +# Apply standard settings, star the repository, configure main branch protection, +# and attempt to enable vulnerability alerts and automated security fixes via gh. +# Arguments: $1 is the repository name within OWNER (without the owner prefix). +# Uses globals OWNER and LOG_FILE; prints progress and appends it to LOG_FILE. configure_repo() { local repo=$1 echo "Configuring: $repo" | tee -a "$LOG_FILE" From bb4a3a1f11ab613213396e378ffd3ca3e1696141 Mon Sep 17 00:00:00 2001 From: "coderabbitai[bot]" <136622811+coderabbitai[bot]@users.noreply.github.com> Date: Wed, 30 Sep 2026 16:20:43 +0000 Subject: [PATCH 3/3] fix(github-admin): abort repository configuration when log setup fails --- .../scripts/github-admin/configure-all-repos.sh | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/personal-sysadmin/scripts/github-admin/configure-all-repos.sh b/personal-sysadmin/scripts/github-admin/configure-all-repos.sh index bf26d2f4..f804fb84 100755 --- a/personal-sysadmin/scripts/github-admin/configure-all-repos.sh +++ b/personal-sysadmin/scripts/github-admin/configure-all-repos.sh @@ -3,10 +3,10 @@ OWNER="hyperpolymath" LOG_FILE="${XDG_STATE_HOME:-$HOME/.local/state}/personal-sysadmin/repo-config.log" -mkdir -p "$(dirname "$LOG_FILE")" -chmod 0700 "$(dirname "$LOG_FILE")" +mkdir -p "$(dirname "$LOG_FILE")" || exit 1 +chmod 0700 "$(dirname "$LOG_FILE")" || exit 1 -echo "Starting configuration of all repos at $(date)" | tee "$LOG_FILE" +echo "Starting configuration of all repos at $(date)" | tee "$LOG_FILE" || exit 1 # Apply standard settings, star the repository, configure main branch protection, # and attempt to enable vulnerability alerts and automated security fixes via gh.