Harden framework: tests, VRAM Python, dashboard spec, security, CI

- Rewrite vram_detect in Python with fixed config parsing and 10KB read limit

- Add pytest suite (72 tests) covering dashboard core, app security, and VRAM

- Standardize all prompts to .automaton/tasks/{task-name}/ path

- Reconcile dashboard spec with web implementation; remove themes.py

- Remove half-implemented refresh.py file watcher

- Harden dashboard static-file serving and task-name validation

- Add uncommitted-change guard to update.sh and real Gitea URLs

- Add AGENTS.md, Gitea CI workflow, and template documentation
This commit is contained in:
2026-06-14 11:24:36 -04:00
parent cc2e97bd43
commit 79b783864e
76 changed files with 2025 additions and 892 deletions
@@ -0,0 +1,26 @@
# Implementation: Rewrite VRAM Detection as Python Script
## Summary
Replaced `scripts/vram_detect.sh` with `scripts/vram_detect.py`, a testable Python implementation that produces the same JSON output and fixes several bugs.
## Files Changed
- `scripts/vram_detect.py` (new)
- `scripts/vram_detect.sh` (deleted)
- `scripts/install.sh` — updated to run Python script and parse JSON with Python
- `README.md` — updated references
- `prompts/onboarding.md` — updated references and invocation
- `prompts/decompose.md` — updated references
- `prompts/orchestrate.md` — updated references
## Bugs Fixed
- Undefined `$headroom_pct` in manual mode.
- Hardcoded `"headroom": 0.25` in JSON output.
- Code-block values in `config.md` being parsed as live config.
- GPU-counting/output ordering bug.
- 10KB file-read limit now enforced for API config files.
## Verification
- `python scripts/vram_detect.py` runs and emits valid JSON.
- `python scripts/vram_detect.py gpt-4o` detects 128k context.
- `python scripts/vram_detect.py --model claude-3-5-sonnet` detects 200k context.
- `rg "vram_detect\.sh" README.md scripts/install.sh prompts/` returns no matches.
@@ -0,0 +1,4 @@
# Review
- **Status**: approved
- **Timestamp**: 2026-06-14T09:59:39.216341
- **Comment**:
@@ -0,0 +1,32 @@
# SPEC: Rewrite VRAM Detection as Python Script
## Goal
Replace the fragile `scripts/vram_detect.sh` with a testable Python script that produces the same JSON output.
## Requirements
1. Create `scripts/vram_detect.py` with the same CLI interface:
- `--model` / `-m`
- `--project` / `-p`
- Optional positional model name
2. Preserve the human-readable output sections and the `=== JSON Output ===` block.
3. Fix known bugs:
- Undefined `$headroom_pct` in manual mode.
- Hardcoded `"headroom": 0.25` in JSON output.
- GPU-counting/output ordering bug.
- Enforce 10KB file-read limit for API config files.
4. Delete `scripts/vram_detect.sh`.
5. Update references in `prompts/orchestrate.md`, `prompts/decompose.md`, `prompts/onboarding.md`, `README.md`, and `config.md` to point to the Python script.
## Acceptance Criteria
- [ ] `python scripts/vram_detect.py` runs and emits valid JSON.
- [ ] Manual-mode headroom is read from `config.md`, not hardcoded.
- [ ] Large API config files are read with a 10KB limit.
- [ ] `scripts/vram_detect.sh` no longer exists.
- [ ] All prompts/docs reference the Python script.
## Non-Goals
- Changing the recommendation algorithm.
- Adding GPU vendor detection beyond Linux `nvidia-smi`, `lspci`, and `/proc/meminfo`.
## Stop Condition
When all acceptance criteria are met, output "CONTRACT_MET".
@@ -0,0 +1,19 @@
# Verdict: Rewrite VRAM Detection as Python Script
## Status: PASS
**Completion Date**: 2026-06-14
## Summary
`scripts/vram_detect.sh` has been replaced by `scripts/vram_detect.py`. The new script is more testable, fixes config-parsing bugs, and preserves the existing CLI and JSON output format.
## Findings
- New Python script created and made executable.
- Old shell script deleted.
- All references in prompts, README, and install script updated.
- Manual runs with and without model arguments succeed and produce valid JSON.
## Remaining Issues
None.
## Score
+10 PASS