Harden framework: tests, VRAM Python, dashboard spec, security, CI

- Rewrite vram_detect in Python with fixed config parsing and 10KB read limit

- Add pytest suite (72 tests) covering dashboard core, app security, and VRAM

- Standardize all prompts to .automaton/tasks/{task-name}/ path

- Reconcile dashboard spec with web implementation; remove themes.py

- Remove half-implemented refresh.py file watcher

- Harden dashboard static-file serving and task-name validation

- Add uncommitted-change guard to update.sh and real Gitea URLs

- Add AGENTS.md, Gitea CI workflow, and template documentation
This commit is contained in:
2026-06-14 11:24:36 -04:00
parent cc2e97bd43
commit 79b783864e
76 changed files with 2025 additions and 892 deletions
@@ -0,0 +1,30 @@
# SPEC: Standardize Task Path Conventions
## Goal
Ensure every prompt uses the canonical task path `{project}/.automaton/tasks/{task-name}/`.
## Requirements
1. Update all prompts under `prompts/` that reference task paths:
- `research.md`
- `design.md`
- `test_design.md`
- `implement.md`
- `bug_finder.md`
- `adversarial_bug_find.md`
- `doc_review.md`
- `referee.md`
- `decompose.md`
- `onboarding.md`
- `compaction.md`
2. Update `templates/tasks/*` artifacts if they contain legacy paths.
3. Add a regression test `tests/test_prompt_paths.py` that fails if any prompt reintroduces the deprecated `{project}/tasks/{task-name}/` path.
## Acceptance Criteria
- [ ] No prompt references `{project}/tasks/{task-name}/` without `.automaton/`.
- [ ] Regression test exists and passes.
## Non-Goals
- Changing any prompt semantics beyond path strings.
## Stop Condition
When all acceptance criteria are met, output "CONTRACT_MET".