Files
automaton/CHANGELOG.md
T
gitea 79b783864e Harden framework: tests, VRAM Python, dashboard spec, security, CI
- Rewrite vram_detect in Python with fixed config parsing and 10KB read limit

- Add pytest suite (72 tests) covering dashboard core, app security, and VRAM

- Standardize all prompts to .automaton/tasks/{task-name}/ path

- Reconcile dashboard spec with web implementation; remove themes.py

- Remove half-implemented refresh.py file watcher

- Harden dashboard static-file serving and task-name validation

- Add uncommitted-change guard to update.sh and real Gitea URLs

- Add AGENTS.md, Gitea CI workflow, and template documentation
2026-06-14 11:24:36 -04:00

5.3 KiB

Changelog

[unreleased]

Added

  • pytest test suite covering dashboard core, app security, and VRAM detection (#add-pytest-test-suite)
  • Root pyproject.toml with optional test/dashboard dependency groups (#add-pytest-test-suite)
  • AGENTS.md with build/test commands and conventions (#developer-experience-gitea-ci)
  • .gitea/workflows/ci.yml running py_compile, pytest, and shell script syntax checks (#developer-experience-gitea-ci)
  • templates/README.md documenting the task template examples (#developer-experience-gitea-ci)
  • Blocked phase column between Verification and Resolution on dashboard (#additive-extension-model)
  • Framework self-enforcement rules in .rules.md and system-prompt.md (#framework-self-enforcement)
  • Additive extension model: projects extend via extensions/ dir, never copy framework files (#additive-extension-model)
  • CHANGELOG.md for release notes tracking (#changelog)
  • Framework audit: comprehensive self-consistency check with RESEARCH.md (#framework-audit)

Changed

  • All prompts now use the canonical task path {project}/.automaton/tasks/{task-name}/ (#standardize-task-path-conventions)
  • scripts/vram_detect.sh rewritten as scripts/vram_detect.py for testability and correctness (#rewrite-vram-detection-python)
  • tasks/dashboard-spec.md reconciled with the implemented web dashboard (#reconcile-dashboard-spec)
  • automaton/dashboard/README.md and help modal shortcuts now match the web UI (#reconcile-dashboard-spec)
  • prompts/orchestrate.md: always reads prompts/contracts/scripts from global, project extensions are additive (#additive-extension-model)
  • prompts/onboarding.md: removed diff/merge upgrade, replaced with migration check (#additive-extension-model)
  • README.md: updated upgrade docs for new additive model (#additive-extension-model); added Dashboard section (#dashboard-task-review)
  • scripts/update.sh: simplified to plain git pull (#additive-extension-model)
  • .rules.md: converted from template to concrete rules with Task-Driven Development, VRAM-aware sizing, Changelog, and Self-Improvement sections (#framework-self-enforcement)
  • system-prompt.md: added instruction to read global .rules.md (#framework-self-enforcement)
  • automaton/dashboard/ui/app.py: added review API endpoints (GET/POST /api/task/{name}/review), spec_content in responses, unquote() for URL-encoded task names, path traversal fix (#dashboard-task-review, #spec-in-detail)
  • automaton/dashboard/html/dashboard.js: review UI (badges, buttons, filter), artifact badges, specification display, modal conversion, textarea replacement, display group for approved planning tasks (#dashboard-task-review, #artifact-badges, #spec-in-detail, #task-detail-modal, #review-textarea)
  • automaton/dashboard/html/styles.css: review components, artifact badges, modal layout, textarea styles (#dashboard-task-review, #artifact-badges, #task-detail-modal, #review-textarea)
  • automaton/dashboard/html/index.html: review filter, pending count, modal overlay (#dashboard-task-review, #task-detail-modal)
  • automaton/dashboard/core/task.py: fixed state machine priority — IMPLEMENTATION.md now correctly detected, DOC_REVIEW checked before BUG_REPORT (#implement-task)
  • automaton/dashboard/core/board.py: fixed KanbanBoard — added missing COLUMNS and init (#implement-task)
  • automaton/dashboard/core/refresh.py: improved inotify error handling with explicit fallback messages (#implement-task)

Fixed

  • VRAM detection: undefined headroom, hardcoded JSON headroom, and code-block config parsing (#rewrite-vram-detection-python)
  • VRAM detection: 10KB file-read limit now enforced for API config files (#rewrite-vram-detection-python)
  • Dashboard static file serving: replaced string-prefix path traversal check with Path.relative_to() (#harden-dashboard-security-scripts)
  • Dashboard task name validation: restricted to [A-Za-z0-9_-]+ (#harden-dashboard-security-scripts)
  • scripts/update.sh: now warns and aborts on uncommitted changes before pulling (#harden-dashboard-security-scripts)
  • README/install.sh: replaced placeholder repository URL with real Gitea URL (#harden-dashboard-security-scripts)
  • State machine: IMPLEMENTATION.md was never checked in determine_task_state(), tasks showed as RESEARCH (#implement-task)
  • State machine: DOC_REVIEW checked after BUG_REPORT — wrong priority order (#implement-task)
  • Path traversal: review API accepted task names with ../ allowing writes outside tasks directory (#dashboard-task-review)
  • URL encoding: task names with spaces in API paths were not decoded (#implement-task)
  • Review parsing: comment extraction used fragile conditional, falsy comments (e.g., "0") skipped (#implement-task)
  • Board display: approved planning tasks stayed in Planning column instead of advancing to Design (#dashboard-task-review)

Removed

  • automaton/dashboard/themes.py (vestigial ANSI theme stub) (#reconcile-dashboard-spec)
  • automaton/dashboard/core/refresh.py (half-implemented file watcher; dashboard uses JS polling) (#remove-file-system-watcher)
  • templates/contract-template.md (unused) (#developer-experience-gitea-ci)
  • automaton/dashboard/pyproject.toml (consolidated into root pyproject.toml) (#add-pytest-test-suite)

Migration

  • Project migration script for old-model projects: scripts/migrate-project.sh (#project-migration)
  • Project migration detection in onboarding.md (#project-migration)