Harden framework: tests, VRAM Python, dashboard spec, security, CI

- Rewrite vram_detect in Python with fixed config parsing and 10KB read limit

- Add pytest suite (72 tests) covering dashboard core, app security, and VRAM

- Standardize all prompts to .automaton/tasks/{task-name}/ path

- Reconcile dashboard spec with web implementation; remove themes.py

- Remove half-implemented refresh.py file watcher

- Harden dashboard static-file serving and task-name validation

- Add uncommitted-change guard to update.sh and real Gitea URLs

- Add AGENTS.md, Gitea CI workflow, and template documentation
This commit is contained in:
2026-06-14 11:24:36 -04:00
parent cc2e97bd43
commit 79b783864e
76 changed files with 2025 additions and 892 deletions
@@ -0,0 +1,17 @@
# Implementation: Remove File System Watcher
## Summary
Removed the half-implemented `refresh.py` file system watcher module and updated the dashboard README to reflect the actual client-side polling refresh mechanism.
## Files Changed
- `automaton/dashboard/core/refresh.py` — deleted
- `automaton/dashboard/README.md` — removed watcher from architecture diagram, fixed tree formatting
## Verification
- `automaton/dashboard/core/refresh.py` no longer exists.
- `python -m automaton.dashboard` still starts and refreshes via JS polling.
- `python -m pytest tests/` still passes.
## Decisions
- The dashboard uses client-side polling (`setInterval`) for auto-refresh.
- No replacement watcher was implemented.
@@ -0,0 +1,4 @@
# Review
- **Status**: approved
- **Timestamp**: 2026-06-14T09:59:40.721019
- **Comment**:
+20
View File
@@ -0,0 +1,20 @@
# SPEC: Remove File System Watcher
## Goal
Resolve the half-implemented `refresh.py` module by removing it and documenting the polling-based refresh behavior.
## Requirements
1. Delete `automaton/dashboard/core/refresh.py`.
2. Update `automaton/dashboard/README.md` to state that auto-refresh uses client-side polling.
3. Ensure no imports or references to `refresh.py` remain.
## Acceptance Criteria
- [ ] `automaton/dashboard/core/refresh.py` does not exist.
- [ ] `README.md` accurately describes the polling refresh mechanism.
- [ ] `python -m automaton.dashboard` still starts and refreshes correctly.
## Non-Goals
- Implementing Server-Sent Events or WebSocket push.
## Stop Condition
When all acceptance criteria are met, output "CONTRACT_MET".
@@ -0,0 +1,18 @@
# Verdict: Remove File System Watcher
## Status: PASS
**Completion Date**: 2026-06-14
## Summary
The unused file system watcher module has been removed and documentation now accurately describes the polling-based refresh behavior.
## Findings
- `refresh.py` deleted.
- README architecture diagram cleaned up.
- Tests still pass.
## Remaining Issues
None.
## Score
+10 PASS