Fix 10 audit bugs: path prefix matching, verdict parsing, CORS, stale-task detection, phase mapping
CI / build (push) Has been cancelled

Batch 1 (High severity):
- Bug 1: --audit cat3 now checks .automaton/tasks/ paths
- Bug 4: Verdict PASS/FAIL uses structured ## Status: line parsing
- Bug 5: register-guards.sh checks .json/.jsonc, writes plugin key, strips comments
- Bug 7: --can-edit/--scope-check path prefix uses os.sep boundary

Batch 2 (Medium/Low severity):
- Bug 2: migrate-project.sh find command parentheses for -prune binding
- Bug 3: vram_detect model prefix matching with known-suffix whitelist
- Bug 6: dashboard reads .state file before artifact heuristic fallback
- Bug 8: removed wildcard CORS, added security headers (nosniff, DENY)
- Bug 9: stale-task detection uses .state.lastedit instead of .state mtime
- Bug 10: TEST_PLAN.md maps to test_design (was implement)

249 tests pass (up from 235). All 10 tasks driven through full workflow to completion.
This commit is contained in:
Lap Tran
2026-06-22 10:40:58 -04:00
parent f32f98575b
commit 81ccf548e5
106 changed files with 1643 additions and 436 deletions
+1
View File
@@ -0,0 +1 @@
complete
@@ -0,0 +1,2 @@
research:approved|2026-06-22T14:28:48.259307+00:00|user
code_review:approved|2026-06-22T14:36:53.260572+00:00|user
@@ -0,0 +1,13 @@
# Adversarial Bug Report: fix-vram-model-prefix-match
## Attack Vectors Tested
1. **Empty model name**: Returns 0 (no match) — correct
2. **Model name with only separator**: `:` or `-` alone — no match, correct
3. **Case sensitivity**: `key.lower()` and `name_lower` handle case-insensitive matching correctly
4. **Suffix that partially matches known suffix**: `instruct` vs `instructional` — `instructional` would not match since `split("-")[0]` gives `instructional` which is not in the set
5. **Multiple separators**: `deepseek-r1:7b-instruct` — matches via `:` before reaching `-` check (correct, Ollama tag takes priority)
## Findings
No bugs found.
## Verdict: PASS
@@ -0,0 +1,13 @@
# Bug Report: fix-vram-model-prefix-match
## Scope
Reviewed `scripts/vram_detect.py` `_lookup_model_context()` and `_KNOWN_MODEL_SUFFIXES` for bugs.
## Findings
No bugs found. The three-tier matching correctly handles:
- Exact matches
- Ollama `:` parameter tags
- Known instruction-tuning suffixes via `-` separator
- Rejects unknown suffixes (prevents false matches)
## Verdict: PASS
@@ -0,0 +1,21 @@
# Code Review: fix-vram-model-prefix-match
## Reviewed Files
- `scripts/vram_detect.py` (`_lookup_model_context()`, `_KNOWN_MODEL_SUFFIXES`)
## Changes
Replaced raw `startswith()` with three-tier matching: exact match, `:` separator (Ollama tags), and `-` separator with known instruction-tuning suffix whitelist.
## Analysis
- **Correctness**: The three-tier approach correctly handles all test cases:
- `deepseek-r1:7b` matches via `:` separator ✓
- `llama-3.1-8b-instruct` matches via `-` + `instruct` suffix ✓
- `phi-4-mini-instruct` rejected (`mini` not in suffixes) ✓
- `gpt-4o-foo-unknown` rejected (`foo` not in suffixes) ✓
- `phi-40` rejected (no separator) ✓
- **Edge cases**: `gpt-4-turbo` is in the dict directly, so it matches via exact match (checked before `gpt-4` due to length-descending sort)
- **Maintainability**: The suffix whitelist is explicit and easy to extend
## Verdict: PASS
The fix is well-structured, handles all edge cases correctly, and is properly tested.
@@ -0,0 +1,12 @@
# Doc Review: fix-vram-model-prefix-match
## Documentation Impact
No documentation changes needed. The fix is internal to `_lookup_model_context()` with no change to user-facing CLI output or behavior.
## Checklist
- [x] No new commands or flags introduced
- [x] AGENTS.md unchanged — no references to model matching internals
- [x] VRAM_CONFIG.md format unchanged
- [x] CHANGELOG.md will be updated for the release
## Verdict: PASS
@@ -0,0 +1,24 @@
# Implementation: fix-vram-model-prefix-match
## Bug
`_lookup_model_context()` in `vram_detect.py` used raw `startswith()` for model name matching, causing false positives like `phi-4` matching `phi-40` or `phi-4-mini-instruct` (a different model with different context window).
## Fix
Replaced the raw `startswith()` with a three-tier matching strategy:
1. **Exact match** — `name_lower == key_lower`
2. **Ollama parameter tag** — `name_lower.startswith(key_lower + ":")` (e.g. `deepseek-r1:7b` matches `deepseek-r1`)
3. **Known instruction-tuning suffix** — `name_lower.startswith(key_lower + "-")` only if the next segment is in `_KNOWN_MODEL_SUFFIXES = {"instruct", "chat", "it", "fp16", "f16", "bf16"}` (e.g. `llama-3.1-8b-instruct` matches `llama-3.1-8b`)
Keys are sorted by length descending so the most specific match wins first.
This prevents false matches:
- `phi-4-mini-instruct` → `mini` not in known suffixes → no match ✓
- `gpt-4o-foo-unknown` → `foo` not in known suffixes → no match ✓
- `phi-40` → no `:` or known-suffix separator → no match ✓
## Files Changed
- `scripts/vram_detect.py`: Added `_KNOWN_MODEL_SUFFIXES` set, rewrote `_lookup_model_context()` with three-tier matching
## Tests
- `test_lookup_model_context_no_false_prefix_match`: Asserts `phi-4-mini-instruct` and `gpt-4o-foo-unknown` return 0
- Existing `test_lookup_model_context_prefix_match` still passes (deepseek-r1:7b and llama-3.1-8b-instruct)
+15
View File
@@ -0,0 +1,15 @@
# Spec: fix-vram-model-prefix-match
## Problem
`scripts/vram_detect.py:396` uses `model_name.lower().startswith(key.lower())` to match model names. This prefix matching causes false matches: `phi-4-mini` matches `phi-4` (16000), and unknown models starting with known prefixes get incorrect context windows instead of the fallback.
## Fix
Try exact match first, then longest-prefix match (sort keys by length descending). Only match if the model name equals the key or starts with `key + "-"` (to avoid `phi-4` matching `phi-40`).
## Acceptance Criteria
- `phi-4-mini-instruct` does NOT match `phi-4` — returns fallback (128000)
- `gpt-4o` still matches `gpt-4o` (exact) — returns 128000
- `gpt-4o-mini` matches `gpt-4o-mini` (exact) — returns 128000
- `claude-3-5-sonnet-20241022` matches exact entry — returns 200000
- Existing tests in `test_vram_detect.py` still pass
- Add test for the prefix edge case
@@ -0,0 +1,13 @@
# Verdict: fix-vram-model-prefix-match
## Status: PASS
## Summary
Fixed `_lookup_model_context()` false prefix matches by replacing raw `startswith()` with three-tier matching: exact, `:` separator (Ollama tags), and `-` separator with known instruction-tuning suffix whitelist. Well-tested with positive and negative cases.
## Artifacts
- IMPLEMENTATION.md: Complete
- CODE_REVIEW.md: PASS
- BUG_REPORT.md: No bugs found
- ADVERSARIAL_BUG_REPORT.md: No bugs found
- DOC_REVIEW.md: PASS