Files
Lap Tran bc7daf8590 Restore archived tasks, fix dashboard scroll-reset, bind ornith, add Playwright smoke test
- **Restore 82 completed tasks** from tasks/complete/ back to tasks/ top
  level (all <7 days old per the cleanup policy; premature bulk archive
  was fixed).
- **Dashboard: fix scroll-reset on auto-refresh** — renderBoard rebuilds
  the board via innerHTML every 2s, destroying each column-body's
  scrollTop. Now snapshots column-body scrollTop + board.scrollLeft +
  view.scrollTop before rebuild and restores after (matched by
  PHASE_GROUPS index).
- **Dashboard UI additions** (pre-existing unstaged work): approval
  section cards, transition buttons, inline artifact editor (textarea for
  writing missing SPEC/VERDICT/etc from the detail modal).
- **Bind ornith as Implement model** — config.md: Model explicit to
  omlx/Ornith-1.0-35B-4bit-mlx, context window 32768. Interactive
  autopilot already used ornith via opencode default; now explicit.
- **Fix cleanup stub** — automaton-cleanup.sh had a stale --project arg
  pointing at a pytest temp dir (test isolation leak). Rewired to point
  at ~/.automaton.
- **Fix plist-isolation test** — test asserted host plist doesn't exist,
  but a real install creates it. Now snapshots mtime before run, asserts
  unchanged after (only a write during the test counts as bleed).
- **New Playwright smoke test** (tests/test_dashboard_ui.py) — 2 tests:
  board renders tasks, column scroll survives auto-refresh tick.
  Verified the test fails without the scroll fix (scrollTop resets to 0).
  Skipped via importorskip when playwright is absent (main CI stays
  green).
- **Clarify SI loop scope in README** — new-project onboarding section
  documents the framework-scoped self-improvement loop and options
  (leave/pause/create project loop).
- **CHANGELOG** documents all changes including the known model-divergence
  gap (mde tasks marked complete but per-role model binding was never
  implemented).
2026-06-26 10:05:18 -04:00

3.2 KiB

ADVERSARIAL_BUG_REPORT: add-blast-radius-scheduler

Attack the worktree creation as a hostile environment would: escape blast radius, inject branch names, or corrupt state.

Attack vectors tried

A1 -- Can a hostile loop.json set worktree_path to an arbitrary location?

_ensure_worktree reads state["worktree_path"], not loop.json. The state file is controlled by the framework (written via _write_state_loop). A hostile loop.json cannot set worktree_path directly. The worktree path is always constructed as <loop_path>/worktree by the runner. PASS

A2 -- Can a hostile loop name create a branch outside the loop/ namespace?

The branch name is f"loop/{loop_name}" where loop_name comes from state.get("name") or loop_path.name. The loop name is validated by _is_kebab_case in status.py --create-loop (rejects non-kebab-case names, including slashes). So the branch name is always loop/<kebab-case-name>. A hostile state file could set name to ../evil, but _write_state_loop is only called by the framework. If the state file is manually edited, the attacker already has filesystem access. PASS (config-trust model).

A3 -- Can git worktree add be coerced into writing outside the loop dir?

The worktree path is <loop_path>/worktree which is under .automaton/loops/<name>/. The git worktree add command receives this as an absolute path. Git creates the worktree at exactly that path. No path traversal possible because the path is constructed from Path objects, not string concatenation. PASS

A4 -- Can a concurrent tick create two worktrees?

TOCTOU: two ticks both see worktree_path is null, both call git worktree add <same-path>. The second call fails because the path exists. The second tick falls back to project root. The first tick succeeds and records the worktree. No state corruption (atomic write; last-writer-wins, but the second write doesn't happen because the fallback path doesn't write state). Next tick: both see the worktree exists and reuse it. PASS (bounded by scheduler interval).

A5 -- Can git worktree add execute arbitrary commands via the branch name?

The branch name is loop/<kebab-case-name>. It's passed as a separate argv element to subprocess.run(["git", "worktree", "add", path, "-b", branch]). No shell invocation (shell=False by default in subprocess.run with list args). A branch name starting with - would be interpreted as a git flag, but _is_kebab_case requires alphanumeric + hyphens + dots + underscores, and the loop/ prefix ensures the branch never starts with -. PASS

If an attacker creates a symlink from <loop_path>/worktree to /etc, git worktree add would fail (git refuses to use existing paths). If the attacker creates the symlink AFTER worktree creation but BEFORE the harness runs, the harness would write to the symlink target. But the attacker needs filesystem access to create the symlink, which already implies compromise. PASS (filesystem-trust model).

Verdict

PASS -- no exploitable escape. Worktree creation is path-safe, branch-name-safe, and shell-injection-safe. TOCTOU is bounded by scheduler interval.