Fix 10 audit bugs: path prefix matching, verdict parsing, CORS, stale-task detection, phase mapping
CI / build (push) Has been cancelled
CI / build (push) Has been cancelled
Batch 1 (High severity): - Bug 1: --audit cat3 now checks .automaton/tasks/ paths - Bug 4: Verdict PASS/FAIL uses structured ## Status: line parsing - Bug 5: register-guards.sh checks .json/.jsonc, writes plugin key, strips comments - Bug 7: --can-edit/--scope-check path prefix uses os.sep boundary Batch 2 (Medium/Low severity): - Bug 2: migrate-project.sh find command parentheses for -prune binding - Bug 3: vram_detect model prefix matching with known-suffix whitelist - Bug 6: dashboard reads .state file before artifact heuristic fallback - Bug 8: removed wildcard CORS, added security headers (nosniff, DENY) - Bug 9: stale-task detection uses .state.lastedit instead of .state mtime - Bug 10: TEST_PLAN.md maps to test_design (was implement) 249 tests pass (up from 235). All 10 tasks driven through full workflow to completion.
This commit is contained in:
@@ -5,7 +5,7 @@
|
||||
# Called by install.sh and update.sh during framework setup.
|
||||
#
|
||||
# Detection:
|
||||
# - OpenCode: checks for ~/.config/opencode/opencode.jsonc
|
||||
# - OpenCode: checks for ~/.config/opencode/opencode.json or .jsonc
|
||||
# - Pi Dev: checks for `pi` in PATH
|
||||
#
|
||||
# Usage: bash ~/.automaton/scripts/register-guards.sh
|
||||
@@ -20,18 +20,30 @@ echo ""
|
||||
echo "=== Pre-Edit Guard Registration ==="
|
||||
|
||||
# OpenCode guard
|
||||
OPENCODE_CONFIG="$HOME/.config/opencode/opencode.jsonc"
|
||||
# Check for both opencode.json (default) and opencode.jsonc
|
||||
OPENCODE_CONFIG=""
|
||||
for candidate in "$HOME/.config/opencode/opencode.json" "$HOME/.config/opencode/opencode.jsonc"; do
|
||||
if [ -f "$candidate" ]; then
|
||||
OPENCODE_CONFIG="$candidate"
|
||||
break
|
||||
fi
|
||||
done
|
||||
OPENCODE_SOURCE="$FRAMEWORK_DIR/plugins/automaton-guard"
|
||||
if [ -f "$OPENCODE_CONFIG" ]; then
|
||||
if [ -n "$OPENCODE_CONFIG" ]; then
|
||||
if grep -q "automaton-guard" "$OPENCODE_CONFIG" 2>/dev/null; then
|
||||
echo "OpenCode: already registered"
|
||||
else
|
||||
echo "OpenCode: registering guard plugin..."
|
||||
# Use 'plugin' key (singular) per opencode config schema.
|
||||
# Strip // comments (JSONC) before parsing for robustness.
|
||||
python3 -c "
|
||||
import json
|
||||
import json, re
|
||||
with open('$OPENCODE_CONFIG') as f:
|
||||
cfg = json.load(f)
|
||||
cfg.setdefault('plugins', []).append('$OPENCODE_SOURCE')
|
||||
text = f.read()
|
||||
# Strip single-line // comments (JSONC) outside of strings
|
||||
text = re.sub(r'//.*?\$', '', text)
|
||||
cfg = json.loads(text)
|
||||
cfg.setdefault('plugin', []).append('$OPENCODE_SOURCE')
|
||||
with open('$OPENCODE_CONFIG', 'w') as f:
|
||||
json.dump(cfg, f, indent=2)
|
||||
"
|
||||
@@ -39,7 +51,7 @@ with open('$OPENCODE_CONFIG', 'w') as f:
|
||||
echo "OpenCode: registered (restart opencode to activate)"
|
||||
fi
|
||||
else
|
||||
echo "OpenCode: not detected (no $OPENCODE_CONFIG)"
|
||||
echo "OpenCode: not detected (no ~/.config/opencode/opencode.json or .jsonc)"
|
||||
fi
|
||||
|
||||
# Pi Dev guard
|
||||
@@ -64,7 +76,7 @@ if $INSTALLED_OPENCODE || $INSTALLED_PI; then
|
||||
fi
|
||||
if ! $INSTALLED_OPENCODE && ! $INSTALLED_PI; then
|
||||
echo "No harness detected. To install a guard manually:"
|
||||
echo " OpenCode: add '\"plugins\": [\"$OPENCODE_SOURCE\"]' to $OPENCODE_CONFIG"
|
||||
echo " OpenCode: add '\"plugin\": [\"$OPENCODE_SOURCE\"]' to ~/.config/opencode/opencode.json"
|
||||
echo " Pi Dev: pi install $PI_SOURCE"
|
||||
echo ""
|
||||
echo "Without a pre-edit guard, git hooks (pre-commit + pre-push)"
|
||||
|
||||
Reference in New Issue
Block a user