diff --git a/ui/launcher/README.adoc b/ui/launcher/README.adoc index 84c967a..4973d91 100644 --- a/ui/launcher/README.adoc +++ b/ui/launcher/README.adoc @@ -109,7 +109,7 @@ keepopen.sh APP_NAME REPO_DIR "GUI_CMD" "TUI_CMD" [LOG_FILE] keepopen.sh betlang-playground /opt/betlang/ui \ "deno task dev" \ "deno task dev --no-browser" \ - /tmp/betlang-playground.log + "${XDG_STATE_HOME:-$HOME/.local/state}/launch-scaffolder/betlang-playground/server.log" ---- == Usage diff --git a/ui/launcher/betlang-playground.sh b/ui/launcher/betlang-playground.sh index 6a06ef1..5a14f60 100755 --- a/ui/launcher/betlang-playground.sh +++ b/ui/launcher/betlang-playground.sh @@ -24,7 +24,12 @@ STANDARDS_COMPLIANCE="launcher-standard-0.2.0" # Use Python's simple HTTP server, falling back to PHP, then Deno GUI_CMD="python3 -m http.server 3000" TUI_CMD="python3 -m http.server 3000" -LOG_FILE="/tmp/${APP_NAME}.log" +# CWE-377: a predictable /tmp log path lets another local user pre-create or +# symlink the file. Durable + re-findable (not scratch): --logs/--tail in a +# separate invocation must find what --start wrote. +LOG_FILE="${XDG_STATE_HOME:-$HOME/.local/state}/launch-scaffolder/${APP_NAME}/server.log" +mkdir -p "$(dirname "$LOG_FILE")" +chmod 0700 "$(dirname "$LOG_FILE")" # Required modes per launcher-standard_praxis.deed MODES=("--start" "--stop" "--status" "--auto" "--browser" "--integ" "--disinteg" "--help" "--debug" "--logs" "--tail") @@ -92,6 +97,11 @@ mode_help() { # Mode: --start # ============================================================================ +# Start the playground through keepopen.sh's GUI/TUI/shell fallback ladder, +# passing the public directory and configured LOG_FILE. +# Exits with status 1 if pgrep finds a command line matching "http.server". +# Replaces the current process; the wrapper determines the eventual exit status. +# Failure to execute the wrapper terminates the launcher. mode_start() { local port="${BETLANG_PORT:-3000}" @@ -110,7 +120,7 @@ mode_start() { "$PROJECT_ROOT/public" \ "cd $PROJECT_ROOT/public && $GUI_CMD" \ "cd $PROJECT_ROOT/public && $TUI_CMD" \ - "/tmp/${APP_NAME}.log" + "$LOG_FILE" } # ============================================================================ diff --git a/ui/launcher/keepopen.sh b/ui/launcher/keepopen.sh index 3324674..cbe3962 100755 --- a/ui/launcher/keepopen.sh +++ b/ui/launcher/keepopen.sh @@ -22,7 +22,16 @@ APP_NAME="${1:-betlang-playground}" REPO_DIR="${2:-"(unknown)"}" GUI_CMD="${3:-"echo GUI mode not configured"}" TUI_CMD="${4:-"echo TUI mode not configured"}" -LOG_FILE="${5:-/tmp/${APP_NAME}.log}" +# CWE-377: a predictable /tmp log path lets another local user pre-create or +# symlink the file. Default matches betlang-playground.sh's LOG_FILE so a run +# without an explicit 5th arg still lands under the same durable, re-findable +# path a caller's --logs/--tail can find. +LOG_FILE="${5:-${XDG_STATE_HOME:-$HOME/.local/state}/launch-scaffolder/${APP_NAME}/server.log}" +mkdir -p "$(dirname "$LOG_FILE")" +# Only restrict permissions on the default application log directory. +if [ -z "${5:-}" ]; then + chmod 0700 "$(dirname "$LOG_FILE")" +fi # Banner colors per stage GUI_COLOR="yellow" @@ -166,8 +175,7 @@ log "Repo directory: $REPO_DIR" log "Log file: $LOG_FILE" log "========================================" -# Ensure log directory exists -mkdir -p "$(dirname "$LOG_FILE")" 2>/dev/null || true +# Log directory already created during configuration above. # Write initial marker log "Launch attempt started at $(date)"