Fix 10 audit bugs: path prefix matching, verdict parsing, CORS, stale-task detection, phase mapping
CI / build (push) Has been cancelled

Batch 1 (High severity):
- Bug 1: --audit cat3 now checks .automaton/tasks/ paths
- Bug 4: Verdict PASS/FAIL uses structured ## Status: line parsing
- Bug 5: register-guards.sh checks .json/.jsonc, writes plugin key, strips comments
- Bug 7: --can-edit/--scope-check path prefix uses os.sep boundary

Batch 2 (Medium/Low severity):
- Bug 2: migrate-project.sh find command parentheses for -prune binding
- Bug 3: vram_detect model prefix matching with known-suffix whitelist
- Bug 6: dashboard reads .state file before artifact heuristic fallback
- Bug 8: removed wildcard CORS, added security headers (nosniff, DENY)
- Bug 9: stale-task detection uses .state.lastedit instead of .state mtime
- Bug 10: TEST_PLAN.md maps to test_design (was implement)

249 tests pass (up from 235). All 10 tasks driven through full workflow to completion.
This commit is contained in:
Lap Tran
2026-06-22 10:40:58 -04:00
parent f32f98575b
commit 81ccf548e5
106 changed files with 1643 additions and 436 deletions
+20 -8
View File
@@ -5,7 +5,7 @@
# Called by install.sh and update.sh during framework setup.
#
# Detection:
# - OpenCode: checks for ~/.config/opencode/opencode.jsonc
# - OpenCode: checks for ~/.config/opencode/opencode.json or .jsonc
# - Pi Dev: checks for `pi` in PATH
#
# Usage: bash ~/.automaton/scripts/register-guards.sh
@@ -20,18 +20,30 @@ echo ""
echo "=== Pre-Edit Guard Registration ==="
# OpenCode guard
OPENCODE_CONFIG="$HOME/.config/opencode/opencode.jsonc"
# Check for both opencode.json (default) and opencode.jsonc
OPENCODE_CONFIG=""
for candidate in "$HOME/.config/opencode/opencode.json" "$HOME/.config/opencode/opencode.jsonc"; do
if [ -f "$candidate" ]; then
OPENCODE_CONFIG="$candidate"
break
fi
done
OPENCODE_SOURCE="$FRAMEWORK_DIR/plugins/automaton-guard"
if [ -f "$OPENCODE_CONFIG" ]; then
if [ -n "$OPENCODE_CONFIG" ]; then
if grep -q "automaton-guard" "$OPENCODE_CONFIG" 2>/dev/null; then
echo "OpenCode: already registered"
else
echo "OpenCode: registering guard plugin..."
# Use 'plugin' key (singular) per opencode config schema.
# Strip // comments (JSONC) before parsing for robustness.
python3 -c "
import json
import json, re
with open('$OPENCODE_CONFIG') as f:
cfg = json.load(f)
cfg.setdefault('plugins', []).append('$OPENCODE_SOURCE')
text = f.read()
# Strip single-line // comments (JSONC) outside of strings
text = re.sub(r'//.*?\$', '', text)
cfg = json.loads(text)
cfg.setdefault('plugin', []).append('$OPENCODE_SOURCE')
with open('$OPENCODE_CONFIG', 'w') as f:
json.dump(cfg, f, indent=2)
"
@@ -39,7 +51,7 @@ with open('$OPENCODE_CONFIG', 'w') as f:
echo "OpenCode: registered (restart opencode to activate)"
fi
else
echo "OpenCode: not detected (no $OPENCODE_CONFIG)"
echo "OpenCode: not detected (no ~/.config/opencode/opencode.json or .jsonc)"
fi
# Pi Dev guard
@@ -64,7 +76,7 @@ if $INSTALLED_OPENCODE || $INSTALLED_PI; then
fi
if ! $INSTALLED_OPENCODE && ! $INSTALLED_PI; then
echo "No harness detected. To install a guard manually:"
echo " OpenCode: add '\"plugins\": [\"$OPENCODE_SOURCE\"]' to $OPENCODE_CONFIG"
echo " OpenCode: add '\"plugin\": [\"$OPENCODE_SOURCE\"]' to ~/.config/opencode/opencode.json"
echo " Pi Dev: pi install $PI_SOURCE"
echo ""
echo "Without a pre-edit guard, git hooks (pre-commit + pre-push)"