# Bug Report: fix-verdict-parsing ## Summary Critical: PASS verdicts that discuss past failures (FAIL/NEEDS_REVIEW) were falsely classified as BLOCKED due to substring-based verdict parsing. State machine had 4 divergences from orchestrator spec. ## Bugs Found ### Bug 1: False-BLOCKED verdict parsing — CRITICAL - **Severity**: Critical - **Location**: `automaton/dashboard/core/task.py:159-169` - **Description**: Substring search for FAIL/NEEDS_REVIEW checked before PASS. A verdict like "## Status: PASS — the previous FAIL finding was resolved" was classified as BLOCKED. - **Reproduction**: Create a VERDICT.md with `## Status: PASS` that mentions the word "FAIL" anywhere in the body. - **Suggested Fix**: Parse structured status lines (`## Status:` / `**Status**:`) first, fall back to substring only for unstructured verdicts. **Fixed.** ### Bug 2: IMPLEMENTATION.md alone shows "Implement" instead of "Bug Find" - **Severity**: Medium - **Location**: `automaton/dashboard/core/task.py:181` - **Description**: A task with only IMPLEMENTATION.md (no BUG_REPORT) showed as "Implement" instead of "Bug Find". The orchestrator spec says this should be Bug Find phase. - **Suggested Fix**: Align state machine with orchestrator. **Fixed.** ### Bug 3: ADVERSARIAL_BUG_REPORT alone shows "Adversarial Bug Find" instead of "Bug Find" - **Severity**: Low - **Location**: `automaton/dashboard/core/task.py:179` - **Description**: Without a BUG_REPORT present, an ADVERSARIAL_BUG_REPORT artifact shouldn't trigger ADV_BUG_FIND per orchestrator spec (which requires BUG_REPORT + SPEC first). Mapped to BUG_FIND for consistency. - **Suggested Fix**: Map ADV alone to BUG_FIND. **Fixed.** ### Bug 4: Filesystem task names bypass validation - **Severity**: Medium - **Location**: `automaton/dashboard/core/task.py:248` - **Description**: Directory names with special characters (quotes, spaces) are served to JS and interpolated into HTML onclick attributes. - **Suggested Fix**: Skip directories with invalid names in `discover_tasks()` and `parse_sub_tasks()`. **Fixed.** ## Score +10 (all critical and medium bugs fixed)