7 memory files covering: - audit-bug-patterns: recurring status.py bug patterns - vram-model-matching: three-tier model prefix matching - dashboard-security: .state priority, CORS removal, register-guards - state-machine-workflow: legal transitions and approval gates - testing-conventions: pytest patterns and helpers - audit-process: report conventions and batch processing - framework-architecture: enforcement layers and key files
1.0 KiB
Audit Bug Patterns in status.py
Recurring issues found during the 10-bug audit (2026-06-22).
1. Path prefix matching without separator boundary
startswith(proj_str) matches sibling directories (e.g. /foo/project-evil matches /foo/project). Always use startswith(proj_str + os.sep) with exact-match fallback.
2. Substring verdict parsing
Using "PASS" in content falsely matches PASS mentioned in FAIL body text. Always use structured parsing (e.g. ## Status: line) before substring fallback.
3. mtime as activity proxy
.state file mtime reflects phase transitions, not actual edit activity. Use a separate .state.lastedit file touched on ALLOWED --can-edit responses for stale-task detection.
4. Artifact-to-phase mapping mismatches
TEST_PLAN.md is produced during test_design, not implement. Always cross-reference artifact filenames with the workflow phase that produces them.
5. Untracked task enforcement
Tasks without .state files must be refused by all operational commands. Run --upgrade to bootstrap them.