Fix 10 audit bugs: path prefix matching, verdict parsing, CORS, stale-task detection, phase mapping
CI / build (push) Has been cancelled

Batch 1 (High severity):
- Bug 1: --audit cat3 now checks .automaton/tasks/ paths
- Bug 4: Verdict PASS/FAIL uses structured ## Status: line parsing
- Bug 5: register-guards.sh checks .json/.jsonc, writes plugin key, strips comments
- Bug 7: --can-edit/--scope-check path prefix uses os.sep boundary

Batch 2 (Medium/Low severity):
- Bug 2: migrate-project.sh find command parentheses for -prune binding
- Bug 3: vram_detect model prefix matching with known-suffix whitelist
- Bug 6: dashboard reads .state file before artifact heuristic fallback
- Bug 8: removed wildcard CORS, added security headers (nosniff, DENY)
- Bug 9: stale-task detection uses .state.lastedit instead of .state mtime
- Bug 10: TEST_PLAN.md maps to test_design (was implement)

249 tests pass (up from 235). All 10 tasks driven through full workflow to completion.
This commit is contained in:
Lap Tran
2026-06-22 10:40:58 -04:00
parent f32f98575b
commit 81ccf548e5
106 changed files with 1643 additions and 436 deletions
+28 -4
View File
@@ -389,14 +389,38 @@ def detect_model_context(
return 0
_KNOWN_MODEL_SUFFIXES = {"instruct", "chat", "it", "fp16", "f16", "bf16"}
def _lookup_model_context(model_name: str) -> int:
"""Look up context window for a known model name."""
# Strip common version/date suffixes for lookup.
for key in MODEL_CONTEXT_WINDOWS:
if model_name.lower().startswith(key.lower()):
"""Look up context window for a known model name.
Tries exact match first, then:
- ``key + ":"`` prefix (Ollama parameter tag, e.g. ``deepseek-r1:7b``)
- ``key + "-"`` prefix only if the next segment is a known instruction-tuning
suffix (e.g. ``llama-3.1-8b-instruct`` matches ``llama-3.1-8b``)
This prevents false matches like ``phi-4`` matching ``phi-4-mini-instruct``
or ``gpt-4o`` matching ``gpt-4o-foo-unknown``.
Longer keys are tried first so the most specific match wins.
"""
name_lower = model_name.lower()
for key in sorted(MODEL_CONTEXT_WINDOWS, key=len, reverse=True):
key_lower = key.lower()
if name_lower == key_lower:
print(f"Model: {model_name}")
print(f"Context window: {MODEL_CONTEXT_WINDOWS[key] // 1000}k tokens")
return MODEL_CONTEXT_WINDOWS[key]
if name_lower.startswith(key_lower + ":"):
print(f"Model: {model_name}")
print(f"Context window: {MODEL_CONTEXT_WINDOWS[key] // 1000}k tokens")
return MODEL_CONTEXT_WINDOWS[key]
if name_lower.startswith(key_lower + "-"):
next_segment = name_lower[len(key_lower) + 1:].split("-")[0]
if next_segment in _KNOWN_MODEL_SUFFIXES:
print(f"Model: {model_name}")
print(f"Context window: {MODEL_CONTEXT_WINDOWS[key] // 1000}k tokens")
return MODEL_CONTEXT_WINDOWS[key]
print(f"Model: {model_name} (unknown context window)")
return 0