State Enforcement (v2.0):
- .state file as single source of truth for task phase
- Approval gates for research, decomposition, design, test_design
- status.py --transition refuses illegal phase transitions
- status.py --validate-folder detects out-of-order artifacts
- status.py --audit checks all tasks for violations
- status.py --create-task is the only valid way to create tasks
- Pre-v2.0 tasks without .state are UNTRACKED -- all commands refuse them
- New --upgrade command bootstraps .state files for existing tasks
Project Scoping:
- --project flag added to all status.py commands across 16+ files
- _find_project_dir errors instead of silently falling back to ~/.automaton/
- --scope-check marks framework files OUT_OF_SCOPE when working on a project
- Dashboard handlers use stored project_root instead of re-detecting from CWD
- Prompts reference ~/.automaton/scripts/vram_detect.py (not {project}/.automaton/)
Harness Integration:
- status.py --can-edit now supports project-level checks (no --task required)
- --can-edit --file checks file scope without --task
- --json output for machine-readable harness integration
- opencode plugin (plugins/automaton-guard/plugin.ts) intercepts edit/write
- Git pre-commit hook (scripts/git-hooks/pre-commit) blocks commits without task
- Formal integration contract (contracts/harness-integration.md)
Other:
- upgrade.sh delegates to status.py --upgrade instead of manual heuristics
- Phase prompts reference --project {project} for multi-project scoping
- 200 tests passing (14 new)
- Rewrite vram_detect in Python with fixed config parsing and 10KB read limit
- Add pytest suite (72 tests) covering dashboard core, app security, and VRAM
- Standardize all prompts to .automaton/tasks/{task-name}/ path
- Reconcile dashboard spec with web implementation; remove themes.py
- Remove half-implemented refresh.py file watcher
- Harden dashboard static-file serving and task-name validation
- Add uncommitted-change guard to update.sh and real Gitea URLs
- Add AGENTS.md, Gitea CI workflow, and template documentation
The agent scanned tasks in invest-copilot while working on automaton
framework, wasting time on unrelated work. Added a rule with concrete
failure example limiting work to the current project's .automaton/tasks/
only.
The orchestrator only drove ONE task per invocation, then stopped with
ORCHESTRATION_COMPLETE. User had to manually re-trigger for each task.
Changes:
- Added drive_all() outer loop that scans EVERY task and drives them all
- Tasks needing user review are flagged; orchestrator continues to next
- Only stops when ALL tasks are terminal or ALL remaining need user input
- Output format now shows session summary (completed, awaiting review, blocked)
- Session-starter references 'orchestrate' as primary command
- Updated continue-from-existing to use drive_all()
Full M3 redesign with Google's color scheme, elevation system,
and component styling.
Color: primary (#8ab4f8 dark / #1a73e8 light), error (#f28b82),
surface tones with proper dark/light contrast
Elevation: M3 shadow system (levels 0-5) with proper opacity per
color scheme
Typography: Roboto / system-ui stack
Components: M3 card radi (8px), column radi (12px), modal radi (16px)
Focus: M3 focus ring (2px with primary-alpha 0.2)
Cards: accent bar, subtle hover elevation lift
update.sh now checks the current project after pulling latest changes.
If it detects stale prompt/contract/script copies or tasks at the
deprecated root-level location, it prompts the user to run migration.
No more needing to know about migrate-project.sh separately.
Both framework and project tasks now live in .automaton/tasks/.
Every project has a .automaton/ directory, so no need for special
scope-based path logic. Removed the dual-convention gap.
Changes:
- Dashboard _find_tasks_dir() and _get_review_path() always use
{root}/.automaton/tasks/ — no scope branching
- migrate-project.sh: moves tasks/ -> .automaton/tasks/ during upgrade
- Orchestrator prompt: all task path references updated to
{project}/.automaton/tasks/
The additive extension model refactor moved prompts/contracts/scripts into
.automaton/ but never addressed where tasks live. Two conventions existed:
framework keeps tasks in .automaton/tasks/, Orchestrator creates project
tasks at tasks/.
Fixes:
- Dashboard _find_tasks_dir() now scope-aware: framework mode prefers
.automaton/tasks/, project mode prefers tasks/ at project root
- migrate-project.sh: if tasks exist in .automaton/tasks/ (old model),
move them to tasks/ (project root)
- Orchestrator prompt: documents that tasks location depends on scope
Dashboard was hardcoded to read tasks from .automaton/tasks/, but the
Orchestrator creates tasks at tasks/ (project root). Added _find_tasks_dir()
that checks both locations and _get_review_path() that reads REVIEW.md
from whichever location the task lives in.
Priority: .automaton/tasks/ first, then tasks/ as fallback.
This handles framework mode (tasks in .automaton/), project mode
(tasks at root), and symlinked projects.
- Add automaton.pth to user site-packages so python -m automaton.dashboard
works from any working directory, not just ~/.automaton/
- Add scripts/dashboard.sh as a convenience wrapper with PYTHONPATH
- Drive all approved tasks to completion with VERDICT.md
- Fix state machine: IMPLEMENTATION.md was never checked in determine_task_state()
- Fix state machine: DOC_REVIEW.md priority wrong (checked after BUG_REPORT)
- Fix board display: approved planning tasks now advance to Design group
- Fix board display: rejected planning tasks move to Blocked group
- Fix path traversal: review API validated task names against ../ injection
- Fix URL encoding: unquote() task names in API path parsing
- Fix comment parsing: robust REVIEW.md read/write, handle falsy comments
- Fix dead code: KanbanBoard class missing COLUMNS and __init__
- Fix inotify: explicit error messages and polling fallback
- Fix review API: validate task names, prevent path traversal
- Update CHANGELOG.md with all changes