Harden framework: tests, VRAM Python, dashboard spec, security, CI
- Rewrite vram_detect in Python with fixed config parsing and 10KB read limit
- Add pytest suite (72 tests) covering dashboard core, app security, and VRAM
- Standardize all prompts to .automaton/tasks/{task-name}/ path
- Reconcile dashboard spec with web implementation; remove themes.py
- Remove half-implemented refresh.py file watcher
- Harden dashboard static-file serving and task-name validation
- Add uncommitted-change guard to update.sh and real Gitea URLs
- Add AGENTS.md, Gitea CI workflow, and template documentation
This commit is contained in:
@@ -3,6 +3,11 @@
|
||||
## [unreleased]
|
||||
|
||||
### Added
|
||||
- pytest test suite covering dashboard core, app security, and VRAM detection (#add-pytest-test-suite)
|
||||
- Root `pyproject.toml` with optional test/dashboard dependency groups (#add-pytest-test-suite)
|
||||
- `AGENTS.md` with build/test commands and conventions (#developer-experience-gitea-ci)
|
||||
- `.gitea/workflows/ci.yml` running py_compile, pytest, and shell script syntax checks (#developer-experience-gitea-ci)
|
||||
- `templates/README.md` documenting the task template examples (#developer-experience-gitea-ci)
|
||||
- Blocked phase column between Verification and Resolution on dashboard (#additive-extension-model)
|
||||
- Framework self-enforcement rules in .rules.md and system-prompt.md (#framework-self-enforcement)
|
||||
- Additive extension model: projects extend via extensions/ dir, never copy framework files (#additive-extension-model)
|
||||
@@ -10,6 +15,10 @@
|
||||
- Framework audit: comprehensive self-consistency check with RESEARCH.md (#framework-audit)
|
||||
|
||||
### Changed
|
||||
- All prompts now use the canonical task path `{project}/.automaton/tasks/{task-name}/` (#standardize-task-path-conventions)
|
||||
- `scripts/vram_detect.sh` rewritten as `scripts/vram_detect.py` for testability and correctness (#rewrite-vram-detection-python)
|
||||
- `tasks/dashboard-spec.md` reconciled with the implemented web dashboard (#reconcile-dashboard-spec)
|
||||
- `automaton/dashboard/README.md` and help modal shortcuts now match the web UI (#reconcile-dashboard-spec)
|
||||
- prompts/orchestrate.md: always reads prompts/contracts/scripts from global, project extensions are additive (#additive-extension-model)
|
||||
- prompts/onboarding.md: removed diff/merge upgrade, replaced with migration check (#additive-extension-model)
|
||||
- README.md: updated upgrade docs for new additive model (#additive-extension-model); added Dashboard section (#dashboard-task-review)
|
||||
@@ -25,6 +34,12 @@
|
||||
- automaton/dashboard/core/refresh.py: improved inotify error handling with explicit fallback messages (#implement-task)
|
||||
|
||||
### Fixed
|
||||
- VRAM detection: undefined headroom, hardcoded JSON headroom, and code-block config parsing (#rewrite-vram-detection-python)
|
||||
- VRAM detection: 10KB file-read limit now enforced for API config files (#rewrite-vram-detection-python)
|
||||
- Dashboard static file serving: replaced string-prefix path traversal check with `Path.relative_to()` (#harden-dashboard-security-scripts)
|
||||
- Dashboard task name validation: restricted to `[A-Za-z0-9_-]+` (#harden-dashboard-security-scripts)
|
||||
- `scripts/update.sh`: now warns and aborts on uncommitted changes before pulling (#harden-dashboard-security-scripts)
|
||||
- README/install.sh: replaced placeholder repository URL with real Gitea URL (#harden-dashboard-security-scripts)
|
||||
- State machine: IMPLEMENTATION.md was never checked in determine_task_state(), tasks showed as RESEARCH (#implement-task)
|
||||
- State machine: DOC_REVIEW checked after BUG_REPORT — wrong priority order (#implement-task)
|
||||
- Path traversal: review API accepted task names with ../ allowing writes outside tasks directory (#dashboard-task-review)
|
||||
@@ -32,6 +47,12 @@
|
||||
- Review parsing: comment extraction used fragile conditional, falsy comments (e.g., "0") skipped (#implement-task)
|
||||
- Board display: approved planning tasks stayed in Planning column instead of advancing to Design (#dashboard-task-review)
|
||||
|
||||
### Removed
|
||||
- `automaton/dashboard/themes.py` (vestigial ANSI theme stub) (#reconcile-dashboard-spec)
|
||||
- `automaton/dashboard/core/refresh.py` (half-implemented file watcher; dashboard uses JS polling) (#remove-file-system-watcher)
|
||||
- `templates/contract-template.md` (unused) (#developer-experience-gitea-ci)
|
||||
- `automaton/dashboard/pyproject.toml` (consolidated into root `pyproject.toml`) (#add-pytest-test-suite)
|
||||
|
||||
### Migration
|
||||
- Project migration script for old-model projects: scripts/migrate-project.sh (#project-migration)
|
||||
- Project migration detection in onboarding.md (#project-migration)
|
||||
|
||||
Reference in New Issue
Block a user