Drive all 4 remaining tasks to completion through full lifecycle
CI / build (push) Has been cancelled

- actionable-phase-guidance: lifecycle artifacts + .state->complete
- harden-enforcement-layers: pre-push hook, install-hooks.sh, register-guards.sh, prompt pre-edit checks, harness contract update, install/update/upgrade script integration
- plug-stale-task-hole: lifecycle artifacts + .state->complete
- port-pi-guard: pi dev guard plugin, package.json, register-guards integration

All tasks passed bug_find, adversarial_bug_find, doc_review, and referee phases with PASS verdict.
This commit is contained in:
2026-06-16 07:28:45 -04:00
parent 21f16b7da2
commit 99ddb98861
43 changed files with 775 additions and 44 deletions
+21 -18
View File
@@ -4,11 +4,12 @@ This document defines the integration contract between the automaton framework a
## Enforcement Layers
The framework provides three enforcement layers, from strongest to weakest:
The framework provides four enforcement layers, from strongest to weakest:
1. **Harness pre-edit hook** (blocks edits before they happen) — primary enforcement
2. **Git pre-commit hook** (blocks commits without a task) — safety net
3. **Prompt-based rules** (ALLOWED/FORBIDDEN sections in phase prompts) — advisory only
2. **Git pre-push hook** (blocks pushes without a task — catches `--no-verify` bypasses)
3. **Git pre-commit hook** (blocks commits without a task) — safety net
4. **Prompt-based rules** (ALLOWED/FORBIDDEN sections in phase prompts) — advisory only
## Layer 1: Harness Pre-Edit Hook
@@ -98,20 +99,21 @@ Each phase prompt includes ALLOWED/FORBIDDEN sections. These are advisory — th
### opencode (pi)
opencode supports plugins with `tool.execute.before` hooks. A plugin is provided at `~/.automaton/plugins/automaton-guard/plugin.ts`.
opencode supports plugins with `tool.execute.before` hooks. A plugin is provided at
`~/.automaton/plugins/automaton-guard/plugin.ts`.
**Installation:**
**Installation** (automatic):
The framework install/update scripts auto-register the plugin in
`~/.config/opencode/opencode.jsonc`. No manual steps needed.
**Manual installation**:
Add to your project's `opencode.json`:
```json
{
"plugin": ["~/.automaton/plugins/automaton-guard"]
"plugins": ["~/.automaton/plugins/automaton-guard"]
}
```
Or install globally via `pi install`.
The plugin intercepts `edit` and `write` tool calls, runs `status.py --can-edit --project {dir} --file {path} --json`, and blocks the edit if DENIED. The agent receives a message explaining why the edit was blocked and how to proceed.
### aider
@@ -138,13 +140,14 @@ Any tool that can execute shell commands before file edits should:
## Enforcement Coverage Matrix
| Harness | Pre-edit hook | Pre-commit hook | Prompt rules |
|---------|:---:|:---:|:---:|
| opencode (pi) | Plugin | Symlink | Yes |
| aider | Manual | Symlink | Yes |
| Cursor | — | Symlink | Yes |
| Copilot | — | Symlink | Yes |
| Cline | — | Symlink | Yes |
| Raw LLM API | — | Symlink | Yes |
| Harness | Pre-edit hook | Pre-push hook | Pre-commit hook | Prompt rules |
|---------|:---:|:---:|:---:|:---:|
| opencode (pi) | Plugin | Symlink | Symlink | Yes |
| Pi Dev | Plugin | Symlink | Symlink | Yes |
| aider | Manual | Symlink | Symlink | Yes |
| Cursor | — | Symlink | Symlink | Yes |
| Copilot | — | Symlink | Symlink | Yes |
| Cline | — | Symlink | Symlink | Yes |
| Raw LLM API | — | Symlink | Symlink | Yes |
Pre-commit hooks work universally because git is universal. Pre-edit hooks require harness support.
Pre-push and pre-commit hooks work universally because git is universal. Pre-edit hooks require harness support.