Files
Lap Tran bc7daf8590 Restore archived tasks, fix dashboard scroll-reset, bind ornith, add Playwright smoke test
- **Restore 82 completed tasks** from tasks/complete/ back to tasks/ top
  level (all <7 days old per the cleanup policy; premature bulk archive
  was fixed).
- **Dashboard: fix scroll-reset on auto-refresh** — renderBoard rebuilds
  the board via innerHTML every 2s, destroying each column-body's
  scrollTop. Now snapshots column-body scrollTop + board.scrollLeft +
  view.scrollTop before rebuild and restores after (matched by
  PHASE_GROUPS index).
- **Dashboard UI additions** (pre-existing unstaged work): approval
  section cards, transition buttons, inline artifact editor (textarea for
  writing missing SPEC/VERDICT/etc from the detail modal).
- **Bind ornith as Implement model** — config.md: Model explicit to
  omlx/Ornith-1.0-35B-4bit-mlx, context window 32768. Interactive
  autopilot already used ornith via opencode default; now explicit.
- **Fix cleanup stub** — automaton-cleanup.sh had a stale --project arg
  pointing at a pytest temp dir (test isolation leak). Rewired to point
  at ~/.automaton.
- **Fix plist-isolation test** — test asserted host plist doesn't exist,
  but a real install creates it. Now snapshots mtime before run, asserts
  unchanged after (only a write during the test counts as bleed).
- **New Playwright smoke test** (tests/test_dashboard_ui.py) — 2 tests:
  board renders tasks, column scroll survives auto-refresh tick.
  Verified the test fails without the scroll fix (scrollTop resets to 0).
  Skipped via importorskip when playwright is absent (main CI stays
  green).
- **Clarify SI loop scope in README** — new-project onboarding section
  documents the framework-scoped self-improvement loop and options
  (leave/pause/create project loop).
- **CHANGELOG** documents all changes including the known model-divergence
  gap (mde tasks marked complete but per-role model binding was never
  implemented).
2026-06-26 10:05:18 -04:00

2.6 KiB

ADVERSARIAL_BUG_REPORT: fix-install-update-flow

Methodology

Targeted attack on:

  1. Shell injection via $GIT_URL
  2. Path traversal via $FRAMEWORK_DIR
  3. Race condition on .venv creation
  4. Hook source file missing
  5. set -e interaction with || true

Findings

Attack 1: Shell injection via $GIT_URL -- NOT VULNERABLE

$GIT_URL is passed as a double-quoted argument to git clone "$GIT_URL" "$FRAMEWORK_DIR". The shell does not interpret special characters inside double quotes in argument position. git clone treats it as a URL, not a shell command. No injection vector.

Verdict: NOT VULNERABLE

Attack 2: Path traversal via $FRAMEWORK_DIR -- NOT VULNERABLE

$FRAMEWORK_DIR is set to $HOME/.automaton at the top of the script. It is not derived from user input. All paths constructed with $FRAMEWORK_DIR are safe.

Verdict: NOT VULNERABLE

Attack 3: Race condition on .venv creation -- NOT EXPLOITABLE

If two installs run concurrently (unlikely for a per-user framework), both might try to create .venv simultaneously. python3 -m venv creates the directory atomically. If it already exists, it updates in place. No data corruption.

Verdict: NOT EXPLOITABLE

Attack 4: Hook source file missing -- HANDLED

All three scripts check [ -f "$HOOK_SRC" ] or [ -f "$SOURCE" ] before copying. If the source is missing, install-hooks.sh prints a WARNING and continues. update.sh skips the hook. upgrade.sh would fail on cp if the source is missing and the check doesn't guard it -- let me verify.

Looking at upgrade.sh:

HOOK_SOURCE="$FRAMEWORK_DIR/scripts/git-hooks/$HOOK"
if [ -f "$HOOK_TARGET" ]; then
    ...
else
    cp "$HOOK_SOURCE" "$HOOK_TARGET"

If $HOOK_SOURCE doesn't exist, cp will fail and set -euo pipefail will cause the script to exit. This is a bug if the framework is corrupted. However, the hooks are part of the framework and should always exist. If they're missing, exiting with an error is the correct behavior (not silent success).

Verdict: ACCEPTABLE (fails loudly on corrupted framework)

Attack 5: set -e interaction with || true -- CORRECT

set -e causes the script to exit on any command failure. cmd || true prevents the exit because the overall command succeeds (the || true branch). The || echo "WARNING: ..." pattern also prevents exit because echo succeeds. This is the standard bash idiom for non-fatal commands.

Verdict: CORRECT

Summary

No exploitable vulnerabilities found. One ACCEPTABLE finding (upgrade.sh fails loudly on corrupted framework, which is correct behavior).

Verdict: CLEAN