Harden framework: tests, VRAM Python, dashboard spec, security, CI
- Rewrite vram_detect in Python with fixed config parsing and 10KB read limit
- Add pytest suite (72 tests) covering dashboard core, app security, and VRAM
- Standardize all prompts to .automaton/tasks/{task-name}/ path
- Reconcile dashboard spec with web implementation; remove themes.py
- Remove half-implemented refresh.py file watcher
- Harden dashboard static-file serving and task-name validation
- Add uncommitted-change guard to update.sh and real Gitea URLs
- Add AGENTS.md, Gitea CI workflow, and template documentation
This commit is contained in:
@@ -0,0 +1,28 @@
|
||||
# Implementation: Add pytest Test Suite
|
||||
|
||||
## Summary
|
||||
Added a comprehensive pytest suite covering the dashboard core modules and the new VRAM detection script.
|
||||
|
||||
## Files Changed
|
||||
- `tests/test_scope.py` (new)
|
||||
- `tests/test_task.py` (new)
|
||||
- `tests/test_board.py` (new)
|
||||
- `tests/test_stats.py` (new)
|
||||
- `tests/test_config.py` (new)
|
||||
- `tests/test_app.py` (new)
|
||||
- `tests/test_vram_detect.py` (new)
|
||||
- `tests/test_prompt_paths.py` (created earlier in Task 5)
|
||||
- `pyproject.toml` (new root config with optional dependencies)
|
||||
- `automaton/dashboard/pyproject.toml` (deleted to avoid conflict)
|
||||
- `.gitignore` (updated for pytest cache, egg-info, venvs)
|
||||
|
||||
## Bug Fixes Found During Testing
|
||||
- `DashboardHandler._validate_task_name` was an instance method; converted to `@staticmethod`.
|
||||
- `scripts/vram_detect.py` regex for override context window did not match `**Override context window**`.
|
||||
- `scripts/vram_detect.py` `_parse_token_value` did not handle decimal values like `5.6k`.
|
||||
|
||||
## Verification
|
||||
- `python -m pytest tests/` passes: **70 tests passed**.
|
||||
|
||||
## Notes
|
||||
- The root `pyproject.toml` now defines `automaton` package discovery and optional dependency groups.
|
||||
@@ -0,0 +1,4 @@
|
||||
# Review
|
||||
- **Status**: approved
|
||||
- **Timestamp**: 2026-06-14T09:59:32.664776
|
||||
- **Comment**:
|
||||
@@ -0,0 +1,29 @@
|
||||
# SPEC: Add pytest Test Suite
|
||||
|
||||
## Goal
|
||||
Add automated tests for the dashboard and the new VRAM detection script.
|
||||
|
||||
## Requirements
|
||||
1. Create `tests/test_scope.py` for scope detection.
|
||||
2. Create `tests/test_task.py` for task state determination and sub-task parsing.
|
||||
3. Create `tests/test_board.py` for Kanban board grouping and filtering.
|
||||
4. Create `tests/test_stats.py` for statistics calculations.
|
||||
5. Create `tests/test_config.py` for config validation and defaults.
|
||||
6. Create `tests/test_app.py` for dashboard HTTP API endpoints and path-traversal guard.
|
||||
7. Create `tests/test_vram_detect.py` for the VRAM detector using mocked system data.
|
||||
8. Update `pyproject.toml` with optional dependencies:
|
||||
- `test` extra: `pytest`
|
||||
- `dashboard` extra: `inotify` (optional)
|
||||
9. Update `.gitignore` for `.pytest_cache/`.
|
||||
|
||||
## Acceptance Criteria
|
||||
- [ ] `python -m pytest` discovers and passes all tests.
|
||||
- [ ] Tests exercise state determination, filtering, API responses, config validation, and VRAM detection.
|
||||
- [ ] `pyproject.toml` includes the optional dependency groups.
|
||||
|
||||
## Non-Goals
|
||||
- Achieving 100% coverage.
|
||||
- Testing shell scripts (handled separately).
|
||||
|
||||
## Stop Condition
|
||||
When all acceptance criteria are met, output "CONTRACT_MET".
|
||||
@@ -0,0 +1,18 @@
|
||||
# Verdict: Add pytest Test Suite
|
||||
|
||||
## Status: PASS
|
||||
**Completion Date**: 2026-06-14
|
||||
|
||||
## Summary
|
||||
A pytest suite has been added covering scope detection, task state determination, board logic, statistics, configuration, dashboard app validation, and VRAM detection. All tests pass.
|
||||
|
||||
## Findings
|
||||
- 70 tests pass.
|
||||
- Root packaging configured.
|
||||
- Minor bugs in `_validate_task_name` and VRAM token parsing were discovered and fixed during test development.
|
||||
|
||||
## Remaining Issues
|
||||
None.
|
||||
|
||||
## Score
|
||||
+10 PASS
|
||||
+74
-101
@@ -1,8 +1,8 @@
|
||||
# Contract: Interactive Dashboard for Automaton Framework
|
||||
# Contract: Interactive Web Dashboard for Automaton Framework
|
||||
|
||||
## Goal
|
||||
|
||||
Build an interactive terminal dashboard that visualizes and monitors task progress within the automaton framework. The dashboard is **scope-aware**: when opened in `~/.automaton/`, it tracks framework development tasks; when opened in any project root (a project that has installed automaton), it tracks that project's tasks.
|
||||
Build an interactive web dashboard that visualizes and monitors task progress within the automaton framework. The dashboard is **scope-aware**: when opened in `~/.automaton/`, it tracks framework development tasks; when opened in any project root (a project that has installed automaton), it tracks that project's tasks.
|
||||
|
||||
## Requirements
|
||||
|
||||
@@ -13,120 +13,94 @@ Build an interactive terminal dashboard that visualizes and monitors task progre
|
||||
- **1.4** The current scope is displayed in the dashboard header.
|
||||
|
||||
### 2. Kanban Board View (Primary View)
|
||||
- **2.1** The board displays tasks as cards organized into columns by their current phase.
|
||||
- **2.2** Columns map directly to the automaton task state machine:
|
||||
- **Backlog** — No artifacts (New state)
|
||||
- **Research** — Has SPEC.md (Research phase)
|
||||
- **Decomposition** — Has SPEC.md + DECOMPOSITION.md (Decomposition phase)
|
||||
- **Design** — Has SPEC.md + DESIGN.md (Design phase)
|
||||
- **Implement** — Has IMPLEMENTATION.md (Implement phase)
|
||||
- **Bug Find** — Has BUG_REPORT.md (Bug Find phase)
|
||||
- **Adversarial Bug Find** — Has ADVERSARIAL_BUG_REPORT.md (Adversarial Bug Find phase)
|
||||
- **Doc Review** — Has DOC_REVIEW.md (Doc Review phase)
|
||||
- **Referee** — Has VERDICT.md (Referee phase)
|
||||
- **Done** — VERDICT.md with PASS (Complete state)
|
||||
- **Blocked** — VERDICT.md with FAIL or NEEDS_REVIEW (Human Intervention)
|
||||
- **2.3** Tasks with sub-tasks show a collapsed indicator (e.g., `[3/5]`) showing sub-task completion progress.
|
||||
- **2.4** Tasks can be expanded to show sub-task details inline.
|
||||
- **2.5** Columns are horizontally scrollable if they overflow the terminal width.
|
||||
- **2.1** The board displays tasks as cards organized into phase groups:
|
||||
- **Planning** — Backlog, Research, Decomposition
|
||||
- **Design** — Design, Test Design
|
||||
- **Implementation** — Implement
|
||||
- **Verification** — Bug Find, Adversarial Bug Find, Doc Review, Referee
|
||||
- **Blocked** — VERDICT.md with FAIL or NEEDS_REVIEW
|
||||
- **Resolution** — VERDICT.md with PASS
|
||||
- **2.2** Tasks with sub-tasks show a progress indicator (e.g., `[3/5]`) showing sub-task completion progress.
|
||||
- **2.3** Columns are horizontally scrollable if they overflow the viewport.
|
||||
|
||||
### 3. Task Cards
|
||||
- **3.1** Each task card displays:
|
||||
- Task name (kebab-case folder name, human-readable)
|
||||
- Current phase/column
|
||||
- Time elapsed since task creation (if timestamp is available)
|
||||
- Current phase
|
||||
- Sub-task progress indicator (if applicable)
|
||||
- Status indicator (e.g., ✅ PASS, ❌ FAIL, ⏸ BLOCKED, 🔄 IN PROGRESS)
|
||||
- **3.2** Cards are selectable with arrow keys or mouse.
|
||||
- **3.3** Selected card shows expanded details in a side panel or bottom panel.
|
||||
- Status indicator (✅ PASS, ❌ FAIL/BLOCKED, 🔄 IN PROGRESS)
|
||||
- Review status badge
|
||||
- **3.2** Cards are clickable to open a detail panel.
|
||||
|
||||
### 4. Task Detail Panel
|
||||
- **4.1** When a task card is selected, the detail panel shows:
|
||||
- Full task name and folder path
|
||||
- Current state/mapping to kanban column
|
||||
- List of artifacts present (SPEC.md, DESIGN.md, etc.) with status
|
||||
- Sub-task list (if applicable) with individual statuses
|
||||
- **4.1** When a task card is clicked, a modal panel shows:
|
||||
- Full task name
|
||||
- Current state and phase group
|
||||
- List of artifacts present with status
|
||||
- Sub-task list with individual statuses
|
||||
- Review buttons (approve / request changes)
|
||||
- VERDICT.md content (if present)
|
||||
- BUG_REPORT.md content (if present)
|
||||
- **4.2** The detail panel is resizable.
|
||||
- **4.3** Navigating away from a task hides the detail panel.
|
||||
- SPEC.md content (if present)
|
||||
|
||||
### 5. Statistics View
|
||||
- **5.1** A statistics view accessible via keybinding shows:
|
||||
- **5.1** A statistics view accessible via tab or keybinding shows:
|
||||
- Total tasks count
|
||||
- Tasks per phase breakdown (bar chart or table)
|
||||
- Tasks per phase group and per state (bar charts)
|
||||
- Pass/Fail/Blocked rate
|
||||
- Average tasks completed per day (if timestamps available)
|
||||
- Current WIP (tasks in progress, not in Backlog or Done)
|
||||
- **5.2** Statistics are calculated in real-time from the `tasks/` directory.
|
||||
- Current WIP (tasks in progress)
|
||||
- Sub-task progress
|
||||
- Wave progress
|
||||
|
||||
### 6. Timeline View
|
||||
- **6.1** A timeline view accessible via keybinding shows:
|
||||
- Tasks arranged by their progress through phases over time
|
||||
- Wave visualization for decomposed tasks (Wave 1, Wave 2, etc.)
|
||||
- Sub-task parallel execution visualization
|
||||
- **6.2** Timeline is scrollable and zoomable.
|
||||
- **6.1** A timeline view shows each task's progress through the lifecycle.
|
||||
- **6.2** Sub-task completion is shown per task.
|
||||
|
||||
### 7. Filtering and Search
|
||||
- **7.1** Filter tasks by phase/status using a filter bar.
|
||||
- **7.2** Filter tasks by sub-task wave (for decomposed tasks).
|
||||
- **7.3** Search tasks by name using a search bar.
|
||||
- **7.4** Filters are combinable (e.g., show only "Research" tasks in Wave 2).
|
||||
- **7.1** Filter tasks by phase/status.
|
||||
- **7.2** Filter tasks by review status.
|
||||
- **7.3** Filter tasks by whether they have sub-task waves.
|
||||
- **7.4** Search tasks by name.
|
||||
|
||||
### 8. Keyboard Navigation
|
||||
- **8.1** Arrow keys to move between columns and cards.
|
||||
- **8.2** `Enter` to expand/collapse selected card or view task details.
|
||||
- **8.3** `Space` to cycle through views (Board → Statistics → Timeline).
|
||||
- **8.4** `q` or `Ctrl+C` to quit.
|
||||
- **8.5** `?` to show keybindings help.
|
||||
- **8.6** `f` to open filter bar.
|
||||
- **8.7** `s` to open search bar.
|
||||
- **8.8** `w` to cycle through waves (for decomposed tasks).
|
||||
- **8.1** `Space` cycles through views (Board → Statistics → Timeline).
|
||||
- **8.2** `1`, `2`, `3` switch to Board/Stats/Timeline views.
|
||||
- **8.3** `t` cycles themes (default → dark → light).
|
||||
- **8.4** `r` manually refreshes data.
|
||||
- **8.5** `f` toggles the filter bar.
|
||||
- **8.6** `s` focuses the search input.
|
||||
- **8.7** `Esc` closes modals and clears search.
|
||||
- **8.8** `?` shows keybindings help.
|
||||
|
||||
### 9. Auto-Refresh
|
||||
- **9.1** The dashboard auto-refreshes when the `tasks/` directory changes (file system watch).
|
||||
- **9.2** Auto-refresh interval: 2 seconds (configurable).
|
||||
- **9.3** Manual refresh triggered by `r` key.
|
||||
- **9.4** Refresh indicator in the header shows when a refresh occurs.
|
||||
- **9.1** The dashboard auto-refreshes via client-side polling (configurable interval).
|
||||
- **9.2** Default auto-refresh interval: 2 seconds.
|
||||
- **9.3** Manual refresh triggered by `r` key or refresh button.
|
||||
|
||||
### 10. Configuration
|
||||
- **10.1** Dashboard settings stored in `{project}/.automaton/dashboard-config.json`:
|
||||
- `auto_refresh_interval`: seconds between auto-refreshes (default: 2)
|
||||
- `default_view`: which view to show on startup ("board", "statistics", "timeline")
|
||||
- `column_width`: minimum width of each column in characters (default: 30)
|
||||
- `show_timelines`: show time elapsed on cards (default: true)
|
||||
- `show_timelines`: show elapsed time indicators (default: true)
|
||||
- `theme`: color theme ("default", "dark", "light")
|
||||
- **10.2** Configuration is scoped to the project (not global).
|
||||
|
||||
### 11. Color Theme
|
||||
- **11.1** Default theme uses ANSI color codes for:
|
||||
- Backlog: gray
|
||||
- Research: blue
|
||||
- Decomposition: purple
|
||||
- Design: cyan
|
||||
- Implement: green
|
||||
- Bug Find: orange
|
||||
- Adversarial Bug Find: red (darker)
|
||||
- Doc Review: yellow
|
||||
- Referee: magenta
|
||||
- Done: green (bright)
|
||||
- Blocked: red
|
||||
- **11.2** Theme is switchable via keybinding (`t` to cycle themes).
|
||||
- **11.1** Three themes are supported via CSS variables: default (dark), dark, light.
|
||||
- **11.2** Theme is switchable via keybinding (`t`) or configuration.
|
||||
|
||||
### 12. Sub-Task Visualization
|
||||
- **12.1** For decomposed tasks, sub-tasks are shown as indented items under the parent task card.
|
||||
- **12.2** Sub-task progress is shown as a fraction (e.g., `[3/5]` = 3 of 5 sub-tasks complete).
|
||||
- **12.3** Clicking a sub-task shows its detail in the detail panel.
|
||||
- **12.4** Sub-task waves are visualized with visual separation in the Timeline view.
|
||||
- **12.2** Sub-task progress is shown as a fraction (e.g., `[3/5]`).
|
||||
- **12.3** Sub-task statuses are shown in the detail panel and timeline.
|
||||
|
||||
### 13. Performance
|
||||
- **13.1** Dashboard renders within 500ms of a refresh (for projects with up to 100 tasks).
|
||||
- **13.2** No blocking I/O during rendering.
|
||||
- **13.3** File system watch uses inotify (Linux) or kqueue (macOS) for efficient change detection.
|
||||
|
||||
### 14. Error Handling
|
||||
- **14.1** If `tasks/` directory is missing, show a "No tasks found" message.
|
||||
- **14.2** If a task artifact file is corrupted or unreadable, show a warning indicator on the card.
|
||||
- **14.2** If a task artifact file is corrupted or unreadable, show a warning indicator.
|
||||
- **14.3** If the dashboard is opened outside any automaton project, show an error and exit gracefully.
|
||||
|
||||
### 15. Documentation
|
||||
@@ -138,30 +112,29 @@ Build an interactive terminal dashboard that visualizes and monitors task progre
|
||||
|
||||
## Non-Goals
|
||||
|
||||
- **15.1** Web UI (browser-based) — this is terminal-only (TUI).
|
||||
- **15.2** Real-time collaboration — single-user only.
|
||||
- **15.3** Task creation/editing — dashboard is read-only for task state.
|
||||
- **15.4** Notification system — no push notifications or alerts.
|
||||
- **15.5** Calendar integration — no date-based scheduling.
|
||||
- **15.6** Integration with external PM tools — standalone only.
|
||||
- Terminal/TUI implementation.
|
||||
- Real-time collaboration — single-user only.
|
||||
- Task creation/editing — dashboard is read-only for task state.
|
||||
- Notification system — no push notifications or alerts.
|
||||
- Calendar integration — no date-based scheduling.
|
||||
- Integration with external PM tools — standalone only.
|
||||
|
||||
---
|
||||
|
||||
## Acceptance Criteria
|
||||
|
||||
- [ ] Dashboard detects scope (framework vs. project) correctly based on cwd
|
||||
- [ ] Board view displays all tasks in correct Kanban columns based on state machine
|
||||
- [ ] Task cards show name, phase, status, and sub-task progress
|
||||
- [ ] Board view displays all tasks in correct phase groups based on state machine
|
||||
- [ ] Task cards show name, phase, status, review badge, and sub-task progress
|
||||
- [ ] Task detail panel shows full task information when selected
|
||||
- [ ] Statistics view shows correct counts per phase and pass/fail rates
|
||||
- [ ] Timeline view shows task progress and wave structure
|
||||
- [ ] Filter bar filters tasks by phase and wave
|
||||
- [ ] Search bar finds tasks by name
|
||||
- [ ] All 11 keyboard bindings (Enter, Space, q, ?, f, s, w, t, r) work correctly
|
||||
- [ ] Auto-refresh works on file system changes with 2-second interval
|
||||
- [ ] Statistics view shows correct counts per phase group and state
|
||||
- [ ] Timeline view shows task progress
|
||||
- [ ] Filter bar filters tasks by phase, review status, waves, and search
|
||||
- [ ] Keyboard bindings `Space`, `1`, `2`, `3`, `t`, `r`, `f`, `s`, `Esc`, `?` work correctly
|
||||
- [ ] Auto-refresh works with configurable interval
|
||||
- [ ] Dashboard configuration file is created and read correctly
|
||||
- [ ] Color themes cycle correctly with 3 themes
|
||||
- [ ] Sub-task visualization shows progress fraction and expandable details
|
||||
- [ ] Sub-task visualization shows progress fraction and statuses
|
||||
- [ ] Dashboard renders within 500ms for 100 tasks
|
||||
- [ ] Error handling works for missing tasks/ directory and corrupted artifacts
|
||||
- [ ] Documentation includes usage instructions and keybindings reference
|
||||
@@ -170,23 +143,23 @@ Build an interactive terminal dashboard that visualizes and monitors task progre
|
||||
|
||||
## Risks & Mitigations
|
||||
|
||||
- **Risk 1**: Terminal rendering performance degrades with many tasks
|
||||
- Mitigation: Implement virtual rendering (only render visible columns/cards), lazy-load task details
|
||||
- **Risk 2**: File system watch conflicts with agent writing artifacts
|
||||
- Mitigation: Use debounced file system events, handle partial writes gracefully
|
||||
- **Risk 1**: Web rendering performance degrades with many tasks
|
||||
- Mitigation: Efficient DOM updates, client-side filtering, pagination if needed
|
||||
- **Risk 2**: Concurrent reads while agent writes artifacts
|
||||
- Mitigation: Handle read errors gracefully; agents write atomically where possible
|
||||
- **Risk 3**: Task state determination is inconsistent with Orchestrator
|
||||
- Mitigation: Use the same state machine logic as `orchestrate.md` for determining task states
|
||||
- Mitigation: Use the same artifact-based state machine logic as `orchestrate.md`
|
||||
- **Risk 4**: Dashboard breaks when automaton framework is upgraded
|
||||
- Mitigation: Dashboard reads state from the same artifacts the Orchestrator reads; no hardcoded state machine logic — it derives from artifact presence
|
||||
- Mitigation: Dashboard reads state from the same artifacts the Orchestrator reads
|
||||
|
||||
---
|
||||
|
||||
## Notes
|
||||
|
||||
- The dashboard should be a separate module under `~/.automaton/` (e.g., `~/.automaton/dashboard/`) so it can be upgraded independently.
|
||||
- The dashboard uses the same layered file system approach as the Orchestrator — it reads from project's `.automaton/` first, then falls back to global `~/.automaton/`.
|
||||
- Task names in the dashboard should be human-readable. The kebab-case folder name (e.g., `add-user-auth`) should be converted to a display name (e.g., "Add User Auth") by replacing hyphens with spaces and capitalizing.
|
||||
- The dashboard is a **read-only** view of task state — it does not modify or create artifacts. All task lifecycle operations continue through the Orchestrator.
|
||||
- The dashboard is a separate module under `~/.automaton/automaton/dashboard/`.
|
||||
- The dashboard uses the same layered file system approach as the Orchestrator.
|
||||
- Task names in the dashboard should be human-readable.
|
||||
- The dashboard is a **read-only** view of task state.
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -0,0 +1,22 @@
|
||||
# Implementation: Developer Experience and Gitea CI
|
||||
|
||||
## Summary
|
||||
Improved framework maintainability by adding contributor documentation, Gitea CI, packaging configuration, and cleaning up unused template files.
|
||||
|
||||
## Files Changed
|
||||
- `AGENTS.md` (new)
|
||||
- `.gitea/workflows/ci.yml` (new)
|
||||
- `templates/contract-template.md` (deleted)
|
||||
- `templates/README.md` (new)
|
||||
- `CHANGELOG.md` (updated with all recent changes)
|
||||
- `pyproject.toml` (root config created in Task 3)
|
||||
|
||||
## Verification
|
||||
- `AGENTS.md` contains build/test commands and conventions.
|
||||
- `.gitea/workflows/ci.yml` references the correct test commands.
|
||||
- `templates/contract-template.md` no longer exists.
|
||||
|
||||
## Decisions
|
||||
- Gitea is the CI platform (matches existing infrastructure).
|
||||
- CI runs py_compile, pytest, and bash syntax checks.
|
||||
- Unused contract template removed; remaining templates documented.
|
||||
@@ -0,0 +1,4 @@
|
||||
# Review
|
||||
- **Status**: approved
|
||||
- **Timestamp**: 2026-06-14T09:59:36.218164
|
||||
- **Comment**:
|
||||
@@ -0,0 +1,32 @@
|
||||
# SPEC: Developer Experience and Gitea CI
|
||||
|
||||
## Goal
|
||||
Improve framework maintainability with documentation, CI, and cleanup.
|
||||
|
||||
## Requirements
|
||||
1. Create `AGENTS.md` with:
|
||||
- How to run tests
|
||||
- How to run the dashboard
|
||||
- Code/style conventions
|
||||
- How to add/update prompts
|
||||
2. Create `.gitea/workflows/ci.yml` that runs:
|
||||
- `python -m py_compile` on all Python files
|
||||
- `python -m pytest`
|
||||
- `bash -n` on all shell scripts (or `shellcheck` if available)
|
||||
3. Update `pyproject.toml` with optional dependency groups.
|
||||
4. Delete `templates/contract-template.md` (confirmed unused).
|
||||
5. Document remaining templates in `templates/README.md` or `AGENTS.md`.
|
||||
6. Update `CHANGELOG.md` with entries for all completed work.
|
||||
|
||||
## Acceptance Criteria
|
||||
- [ ] `AGENTS.md` exists and is useful to a new contributor.
|
||||
- [ ] Gitea CI file exists and would pass on the current codebase.
|
||||
- [ ] `contract-template.md` is removed.
|
||||
- [ ] `CHANGELOG.md` reflects the new work.
|
||||
|
||||
## Non-Goals
|
||||
- Migrating to GitHub Actions.
|
||||
- Rewriting documentation unrelated to the audit fixes.
|
||||
|
||||
## Stop Condition
|
||||
When all acceptance criteria are met, output "CONTRACT_MET".
|
||||
@@ -0,0 +1,20 @@
|
||||
# Verdict: Developer Experience and Gitea CI
|
||||
|
||||
## Status: PASS
|
||||
**Completion Date**: 2026-06-14
|
||||
|
||||
## Summary
|
||||
Contributor documentation, Gitea CI, and template cleanup are in place. The framework is easier to maintain and has automated checks for regressions.
|
||||
|
||||
## Findings
|
||||
- `AGENTS.md` created.
|
||||
- `.gitea/workflows/ci.yml` created.
|
||||
- `contract-template.md` removed.
|
||||
- `templates/README.md` documents remaining templates.
|
||||
- `CHANGELOG.md` updated.
|
||||
|
||||
## Remaining Issues
|
||||
None.
|
||||
|
||||
## Score
|
||||
+10 PASS
|
||||
@@ -0,0 +1,24 @@
|
||||
# Implementation: Harden Dashboard Security and Fix Scripts
|
||||
|
||||
## Summary
|
||||
Closed security holes in the dashboard static file serving and tightened task name validation. Fixed `update.sh` to warn about uncommitted changes. Replaced placeholder URLs with the real Gitea repository URL. Added artifact integrity guidance.
|
||||
|
||||
## Files Changed
|
||||
- `automaton/dashboard/ui/app.py`
|
||||
- Replaced string-prefix path traversal check with robust `Path.relative_to()` resolution.
|
||||
- Tightened task name validation to allow only `[A-Za-z0-9_-]+`.
|
||||
- Added `import re`.
|
||||
- `tests/test_app.py` — added symlink path-traversal test and static-file happy-path test.
|
||||
- `scripts/update.sh` — added uncommitted-changes check before `git pull`.
|
||||
- `README.md` — replaced placeholder install URL with `http://10.37.0.86:3003/hermes/automaton`.
|
||||
- `scripts/install.sh` — replaced placeholder clone URL with `http://10.37.0.86:3003/hermes/automaton`.
|
||||
- `.rules.md` — added "Artifact Integrity" section with atomic-write guidance.
|
||||
|
||||
## Verification
|
||||
- `python -m pytest tests/` passes: **72 tests passed**.
|
||||
- `bash -n scripts/update.sh` passes.
|
||||
- `bash -n scripts/install.sh` passes.
|
||||
|
||||
## Decisions
|
||||
- Task names are restricted to kebab-case/alphanumeric to prevent filesystem traversal.
|
||||
- Symlinks escaping `html_dir` are rejected with 403.
|
||||
@@ -0,0 +1,4 @@
|
||||
# Review
|
||||
- **Status**: approved
|
||||
- **Timestamp**: 2026-06-14T09:59:34.838092
|
||||
- **Comment**:
|
||||
@@ -0,0 +1,25 @@
|
||||
# SPEC: Harden Dashboard Security and Fix Scripts
|
||||
|
||||
## Goal
|
||||
Close obvious security holes in the dashboard and fix script/documentation bugs identified in the audit.
|
||||
|
||||
## Requirements
|
||||
1. Fix path-traversal guard in `automaton/dashboard/ui/app.py`:
|
||||
- Replace string-prefix check with `Path.relative_to` resolution.
|
||||
2. Tighten task name validation in the review API.
|
||||
3. Add uncommitted-changes warning to `scripts/update.sh` before running `git pull`.
|
||||
4. Replace the placeholder repository URL in `README.md` and `scripts/install.sh` with `http://10.37.0.86:3003/hermes/automaton`.
|
||||
5. Add guidance on atomic artifact writes to `references/stop-hook-pattern.md` or `.rules.md`.
|
||||
|
||||
## Acceptance Criteria
|
||||
- [ ] Path-traversal check uses robust `Path` comparison.
|
||||
- [ ] Tests include path-traversal attempts.
|
||||
- [ ] `update.sh` aborts or warns when local uncommitted changes exist.
|
||||
- [ ] `README.md` and `install.sh` contain the real Gitea URL.
|
||||
|
||||
## Non-Goals
|
||||
- Adding authentication to the dashboard.
|
||||
- Rewriting scripts in another language.
|
||||
|
||||
## Stop Condition
|
||||
When all acceptance criteria are met, output "CONTRACT_MET".
|
||||
@@ -0,0 +1,20 @@
|
||||
# Verdict: Harden Dashboard Security and Fix Scripts
|
||||
|
||||
## Status: PASS
|
||||
**Completion Date**: 2026-06-14
|
||||
|
||||
## Summary
|
||||
Dashboard static file serving now uses a robust path containment check, task names are strictly validated, `update.sh` protects against overwriting local changes, and repository URLs point to the real Gitea instance.
|
||||
|
||||
## Findings
|
||||
- Path traversal check uses `Path.relative_to()`.
|
||||
- Task name regex rejects special characters and path separators.
|
||||
- `update.sh` aborts on uncommitted changes.
|
||||
- README and install script contain the real Gitea URL.
|
||||
- Atomic-write guidance added to `.rules.md`.
|
||||
|
||||
## Remaining Issues
|
||||
None.
|
||||
|
||||
## Score
|
||||
+10 PASS
|
||||
@@ -0,0 +1,18 @@
|
||||
# Implementation: Reconcile Dashboard Spec with Web Implementation
|
||||
|
||||
## Summary
|
||||
Updated the dashboard specification and documentation to reflect the actual web-based implementation, and removed the vestigial TUI theme module.
|
||||
|
||||
## Files Changed
|
||||
- `tasks/dashboard-spec.md` — rewritten for web dashboard
|
||||
- `automaton/dashboard/README.md` — removed `q` quit shortcut, updated theme description, removed themes.py/pyproject.toml from architecture diagram
|
||||
- `automaton/dashboard/html/index.html` — fixed help modal (`t` = cycle themes, removed `q` quit)
|
||||
- `automaton/dashboard/themes.py` — deleted
|
||||
|
||||
## Verification
|
||||
- `grep -i "terminal\|TUI\|ANSI\|arrow key\|resizable" tasks/dashboard-spec.md` returns no inappropriate matches.
|
||||
- `python -m automaton.dashboard` still starts and serves `/`.
|
||||
|
||||
## Decisions
|
||||
- Web dashboard is canonical; TUI-specific acceptance criteria removed.
|
||||
- `themes.py` was a stub for ANSI themes and is no longer needed.
|
||||
@@ -0,0 +1,4 @@
|
||||
# Review
|
||||
- **Status**: approved
|
||||
- **Timestamp**: 2026-06-14T09:59:37.715348
|
||||
- **Comment**:
|
||||
@@ -0,0 +1,25 @@
|
||||
# SPEC: Reconcile Dashboard Spec with Web Implementation
|
||||
|
||||
## Goal
|
||||
Eliminate the mismatch between `tasks/dashboard-spec.md` (which describes a terminal TUI) and the actual web-based dashboard implementation.
|
||||
|
||||
## Requirements
|
||||
1. Rewrite `tasks/dashboard-spec.md` acceptance criteria to describe the implemented web dashboard.
|
||||
2. Update `automaton/dashboard/README.md` help table so shortcuts match the web UI:
|
||||
- `t` cycles themes, not waves.
|
||||
- `q` is documented as browser-only (or removed).
|
||||
3. Update `automaton/dashboard/html/index.html` help modal to match the README.
|
||||
4. Delete `automaton/dashboard/themes.py` (vestigial ANSI theme stub).
|
||||
|
||||
## Acceptance Criteria
|
||||
- [ ] `tasks/dashboard-spec.md` contains no TUI-only requirements (ANSI, arrow keys, terminal width, resizable panels).
|
||||
- [ ] `README.md` and help modal agree on keyboard shortcuts.
|
||||
- [ ] `themes.py` is removed.
|
||||
- [ ] `python -m automaton.dashboard` still starts and serves `/` and `/api/tasks`.
|
||||
|
||||
## Non-Goals
|
||||
- Converting the web dashboard to a TUI.
|
||||
- Adding new dashboard features.
|
||||
|
||||
## Stop Condition
|
||||
When all acceptance criteria are met, output "CONTRACT_MET".
|
||||
@@ -0,0 +1,18 @@
|
||||
# Verdict: Reconcile Dashboard Spec with Web Implementation
|
||||
|
||||
## Status: PASS
|
||||
**Completion Date**: 2026-06-14
|
||||
|
||||
## Summary
|
||||
The dashboard specification now matches the implemented web dashboard. Documentation and help modal shortcuts are consistent, and the unused TUI theme module has been removed.
|
||||
|
||||
## Findings
|
||||
- `tasks/dashboard-spec.md` rewritten for web dashboard.
|
||||
- README and help modal agree on keyboard shortcuts.
|
||||
- `themes.py` removed.
|
||||
|
||||
## Remaining Issues
|
||||
None.
|
||||
|
||||
## Score
|
||||
+10 PASS
|
||||
@@ -0,0 +1,17 @@
|
||||
# Implementation: Remove File System Watcher
|
||||
|
||||
## Summary
|
||||
Removed the half-implemented `refresh.py` file system watcher module and updated the dashboard README to reflect the actual client-side polling refresh mechanism.
|
||||
|
||||
## Files Changed
|
||||
- `automaton/dashboard/core/refresh.py` — deleted
|
||||
- `automaton/dashboard/README.md` — removed watcher from architecture diagram, fixed tree formatting
|
||||
|
||||
## Verification
|
||||
- `automaton/dashboard/core/refresh.py` no longer exists.
|
||||
- `python -m automaton.dashboard` still starts and refreshes via JS polling.
|
||||
- `python -m pytest tests/` still passes.
|
||||
|
||||
## Decisions
|
||||
- The dashboard uses client-side polling (`setInterval`) for auto-refresh.
|
||||
- No replacement watcher was implemented.
|
||||
@@ -0,0 +1,4 @@
|
||||
# Review
|
||||
- **Status**: approved
|
||||
- **Timestamp**: 2026-06-14T09:59:40.721019
|
||||
- **Comment**:
|
||||
@@ -0,0 +1,20 @@
|
||||
# SPEC: Remove File System Watcher
|
||||
|
||||
## Goal
|
||||
Resolve the half-implemented `refresh.py` module by removing it and documenting the polling-based refresh behavior.
|
||||
|
||||
## Requirements
|
||||
1. Delete `automaton/dashboard/core/refresh.py`.
|
||||
2. Update `automaton/dashboard/README.md` to state that auto-refresh uses client-side polling.
|
||||
3. Ensure no imports or references to `refresh.py` remain.
|
||||
|
||||
## Acceptance Criteria
|
||||
- [ ] `automaton/dashboard/core/refresh.py` does not exist.
|
||||
- [ ] `README.md` accurately describes the polling refresh mechanism.
|
||||
- [ ] `python -m automaton.dashboard` still starts and refreshes correctly.
|
||||
|
||||
## Non-Goals
|
||||
- Implementing Server-Sent Events or WebSocket push.
|
||||
|
||||
## Stop Condition
|
||||
When all acceptance criteria are met, output "CONTRACT_MET".
|
||||
@@ -0,0 +1,18 @@
|
||||
# Verdict: Remove File System Watcher
|
||||
|
||||
## Status: PASS
|
||||
**Completion Date**: 2026-06-14
|
||||
|
||||
## Summary
|
||||
The unused file system watcher module has been removed and documentation now accurately describes the polling-based refresh behavior.
|
||||
|
||||
## Findings
|
||||
- `refresh.py` deleted.
|
||||
- README architecture diagram cleaned up.
|
||||
- Tests still pass.
|
||||
|
||||
## Remaining Issues
|
||||
None.
|
||||
|
||||
## Score
|
||||
+10 PASS
|
||||
@@ -0,0 +1,26 @@
|
||||
# Implementation: Rewrite VRAM Detection as Python Script
|
||||
|
||||
## Summary
|
||||
Replaced `scripts/vram_detect.sh` with `scripts/vram_detect.py`, a testable Python implementation that produces the same JSON output and fixes several bugs.
|
||||
|
||||
## Files Changed
|
||||
- `scripts/vram_detect.py` (new)
|
||||
- `scripts/vram_detect.sh` (deleted)
|
||||
- `scripts/install.sh` — updated to run Python script and parse JSON with Python
|
||||
- `README.md` — updated references
|
||||
- `prompts/onboarding.md` — updated references and invocation
|
||||
- `prompts/decompose.md` — updated references
|
||||
- `prompts/orchestrate.md` — updated references
|
||||
|
||||
## Bugs Fixed
|
||||
- Undefined `$headroom_pct` in manual mode.
|
||||
- Hardcoded `"headroom": 0.25` in JSON output.
|
||||
- Code-block values in `config.md` being parsed as live config.
|
||||
- GPU-counting/output ordering bug.
|
||||
- 10KB file-read limit now enforced for API config files.
|
||||
|
||||
## Verification
|
||||
- `python scripts/vram_detect.py` runs and emits valid JSON.
|
||||
- `python scripts/vram_detect.py gpt-4o` detects 128k context.
|
||||
- `python scripts/vram_detect.py --model claude-3-5-sonnet` detects 200k context.
|
||||
- `rg "vram_detect\.sh" README.md scripts/install.sh prompts/` returns no matches.
|
||||
@@ -0,0 +1,4 @@
|
||||
# Review
|
||||
- **Status**: approved
|
||||
- **Timestamp**: 2026-06-14T09:59:39.216341
|
||||
- **Comment**:
|
||||
@@ -0,0 +1,32 @@
|
||||
# SPEC: Rewrite VRAM Detection as Python Script
|
||||
|
||||
## Goal
|
||||
Replace the fragile `scripts/vram_detect.sh` with a testable Python script that produces the same JSON output.
|
||||
|
||||
## Requirements
|
||||
1. Create `scripts/vram_detect.py` with the same CLI interface:
|
||||
- `--model` / `-m`
|
||||
- `--project` / `-p`
|
||||
- Optional positional model name
|
||||
2. Preserve the human-readable output sections and the `=== JSON Output ===` block.
|
||||
3. Fix known bugs:
|
||||
- Undefined `$headroom_pct` in manual mode.
|
||||
- Hardcoded `"headroom": 0.25` in JSON output.
|
||||
- GPU-counting/output ordering bug.
|
||||
- Enforce 10KB file-read limit for API config files.
|
||||
4. Delete `scripts/vram_detect.sh`.
|
||||
5. Update references in `prompts/orchestrate.md`, `prompts/decompose.md`, `prompts/onboarding.md`, `README.md`, and `config.md` to point to the Python script.
|
||||
|
||||
## Acceptance Criteria
|
||||
- [ ] `python scripts/vram_detect.py` runs and emits valid JSON.
|
||||
- [ ] Manual-mode headroom is read from `config.md`, not hardcoded.
|
||||
- [ ] Large API config files are read with a 10KB limit.
|
||||
- [ ] `scripts/vram_detect.sh` no longer exists.
|
||||
- [ ] All prompts/docs reference the Python script.
|
||||
|
||||
## Non-Goals
|
||||
- Changing the recommendation algorithm.
|
||||
- Adding GPU vendor detection beyond Linux `nvidia-smi`, `lspci`, and `/proc/meminfo`.
|
||||
|
||||
## Stop Condition
|
||||
When all acceptance criteria are met, output "CONTRACT_MET".
|
||||
@@ -0,0 +1,19 @@
|
||||
# Verdict: Rewrite VRAM Detection as Python Script
|
||||
|
||||
## Status: PASS
|
||||
**Completion Date**: 2026-06-14
|
||||
|
||||
## Summary
|
||||
`scripts/vram_detect.sh` has been replaced by `scripts/vram_detect.py`. The new script is more testable, fixes config-parsing bugs, and preserves the existing CLI and JSON output format.
|
||||
|
||||
## Findings
|
||||
- New Python script created and made executable.
|
||||
- Old shell script deleted.
|
||||
- All references in prompts, README, and install script updated.
|
||||
- Manual runs with and without model arguments succeed and produce valid JSON.
|
||||
|
||||
## Remaining Issues
|
||||
None.
|
||||
|
||||
## Score
|
||||
+10 PASS
|
||||
@@ -0,0 +1,25 @@
|
||||
# Implementation: Standardize Task Path Conventions
|
||||
|
||||
## Summary
|
||||
Updated all prompts under `prompts/` to use the canonical task path `{project}/.automaton/tasks/{task-name}/` instead of the deprecated `{project}/tasks/{task-name}/`.
|
||||
|
||||
## Files Changed
|
||||
- `prompts/decompose.md`
|
||||
- `prompts/test_design.md`
|
||||
- `prompts/doc_review.md`
|
||||
- `prompts/workflow.md`
|
||||
- `prompts/referee.md`
|
||||
- `prompts/adversarial_bug_find.md`
|
||||
- `prompts/research.md`
|
||||
- `prompts/design.md`
|
||||
- `prompts/implement.md`
|
||||
- `prompts/bug_finder.md`
|
||||
- `tests/test_prompt_paths.py` (new regression test)
|
||||
|
||||
## Verification
|
||||
- `rg "\{project\}/tasks/\{task-name\}" prompts/ templates/` returns no matches.
|
||||
- `python -m pytest tests/test_prompt_paths.py -v` passes (27 tests).
|
||||
|
||||
## Decisions
|
||||
- Templates under `templates/tasks/` did not contain legacy paths.
|
||||
- The regression test lives in `tests/test_prompt_paths.py` and will fail CI if a legacy path is reintroduced.
|
||||
@@ -0,0 +1,4 @@
|
||||
# Review
|
||||
- **Status**: approved
|
||||
- **Timestamp**: 2026-06-14T09:59:50.713408
|
||||
- **Comment**:
|
||||
@@ -0,0 +1,30 @@
|
||||
# SPEC: Standardize Task Path Conventions
|
||||
|
||||
## Goal
|
||||
Ensure every prompt uses the canonical task path `{project}/.automaton/tasks/{task-name}/`.
|
||||
|
||||
## Requirements
|
||||
1. Update all prompts under `prompts/` that reference task paths:
|
||||
- `research.md`
|
||||
- `design.md`
|
||||
- `test_design.md`
|
||||
- `implement.md`
|
||||
- `bug_finder.md`
|
||||
- `adversarial_bug_find.md`
|
||||
- `doc_review.md`
|
||||
- `referee.md`
|
||||
- `decompose.md`
|
||||
- `onboarding.md`
|
||||
- `compaction.md`
|
||||
2. Update `templates/tasks/*` artifacts if they contain legacy paths.
|
||||
3. Add a regression test `tests/test_prompt_paths.py` that fails if any prompt reintroduces the deprecated `{project}/tasks/{task-name}/` path.
|
||||
|
||||
## Acceptance Criteria
|
||||
- [ ] No prompt references `{project}/tasks/{task-name}/` without `.automaton/`.
|
||||
- [ ] Regression test exists and passes.
|
||||
|
||||
## Non-Goals
|
||||
- Changing any prompt semantics beyond path strings.
|
||||
|
||||
## Stop Condition
|
||||
When all acceptance criteria are met, output "CONTRACT_MET".
|
||||
@@ -0,0 +1,18 @@
|
||||
# Verdict: Standardize Task Path Conventions
|
||||
|
||||
## Status: PASS
|
||||
**Completion Date**: 2026-06-14
|
||||
|
||||
## Summary
|
||||
All prompts now use the canonical task path `{project}/.automaton/tasks/{task-name}/`. A regression test prevents reintroduction of the deprecated path.
|
||||
|
||||
## Findings
|
||||
- All 10 affected prompt files updated.
|
||||
- No legacy paths remain in `prompts/` or `templates/`.
|
||||
- Regression test passes.
|
||||
|
||||
## Remaining Issues
|
||||
None.
|
||||
|
||||
## Score
|
||||
+10 PASS
|
||||
Reference in New Issue
Block a user