Skip to content

fix(archimate): stop writing every exported model to /tmp/debug_export.xml - #1224

Merged
rubenvdlinde merged 2 commits into
developmentfrom
fix/no-export-dump-in-tmp
Oct 2, 2026
Merged

rubenvdlinde merged 2 commits into
developmentfrom
fix/no-export-dump-in-tmp

Conversation

@rubenvdlinde

Copy link
Copy Markdown
Contributor

What was wrong

Every ArchiMate export wrote the whole exported model to /tmp/debug_export.xml and logged that at info level (ArchiMateExportService::runQualityAssuranceChecks(), line 2147, a leftover // DEBUG block). Two problems:

  • The model leaked. /tmp is shared by every process on the host, and the file name is fixed. The export holds the organisation's application landscape, which other tenants' processes on a shared host could read.
  • The path was predictable. A pre-placed symlink at that name would have turned every export into a write to wherever it pointed.

Found in a fleet audit for runtime file writes, after thematiq#811.

Fix

The three debug lines are removed. The export already returns its XML to the caller, and the quality checks run on the string. A new ArchiMateExportNoDebugDumpTest fails if the service source writes a file again. I also added the class's missing @spec tag, an inherited phpcs warning in this file.

Verified locally

Check Result
ArchiMateExportNoDebugDumpTest fails on development, passes here
PHPUnit (full suite, in a Nextcloud 34 container) 1,093 tests, 2 errors and 1 failure. The same three fail on a development copy in the same harness (1,092 tests), so none is new.
phpstan no errors
psalm no errors
phpcs on the two touched files 0. The whole tree reports warnings in 56 inherited files.
phpmd 0

🤖 Generated with Claude Code

@rubenvdlinde
rubenvdlinde merged commit 2d3104b into development Oct 2, 2026
4 checks passed
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Quality Report — ConductionNL/stackiq @ 2d3104b

Check PHP Vue Security License Tests
lint ✅
phpcs ✅
phpmd ✅
psalm ✅
phpstan ✅
phpmetrics ✅
eslint ✅
stylelint ✅
build ✅
check-manifest ✅
check-vue-demi ✅
test-l10n ✅
format ✅
check-schema-l10n ✅
check-l10n-js ✅
composer ✅ ✅ 130/130
npm ✅ ✅ 807/807
app:check-code ⏭️
info.xml ✅
REUSE ❌
lockfile sync ✅
PHPUnit ✅
Newman ⏭️
Playwright ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it locally with npx playwright test, or from the Actions tab on a branch with no open pull request into development.
Hydra gates ✅

Quality workflow — 2026-10-02 19:28 UTC

Download the full PDF report from the workflow artifacts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant