Files
automaton/tasks/state-file-enforcement/ADVERSARIAL_BUG_REPORT.md
T
Lap Tran bc7daf8590 Restore archived tasks, fix dashboard scroll-reset, bind ornith, add Playwright smoke test
- **Restore 82 completed tasks** from tasks/complete/ back to tasks/ top
  level (all <7 days old per the cleanup policy; premature bulk archive
  was fixed).
- **Dashboard: fix scroll-reset on auto-refresh** — renderBoard rebuilds
  the board via innerHTML every 2s, destroying each column-body's
  scrollTop. Now snapshots column-body scrollTop + board.scrollLeft +
  view.scrollTop before rebuild and restores after (matched by
  PHASE_GROUPS index).
- **Dashboard UI additions** (pre-existing unstaged work): approval
  section cards, transition buttons, inline artifact editor (textarea for
  writing missing SPEC/VERDICT/etc from the detail modal).
- **Bind ornith as Implement model** — config.md: Model explicit to
  omlx/Ornith-1.0-35B-4bit-mlx, context window 32768. Interactive
  autopilot already used ornith via opencode default; now explicit.
- **Fix cleanup stub** — automaton-cleanup.sh had a stale --project arg
  pointing at a pytest temp dir (test isolation leak). Rewired to point
  at ~/.automaton.
- **Fix plist-isolation test** — test asserted host plist doesn't exist,
  but a real install creates it. Now snapshots mtime before run, asserts
  unchanged after (only a write during the test counts as bleed).
- **New Playwright smoke test** (tests/test_dashboard_ui.py) — 2 tests:
  board renders tasks, column scroll survives auto-refresh tick.
  Verified the test fails without the scroll fix (scrollTop resets to 0).
  Skipped via importorskip when playwright is absent (main CI stays
  green).
- **Clarify SI loop scope in README** — new-project onboarding section
  documents the framework-scoped self-improvement loop and options
  (leave/pause/create project loop).
- **CHANGELOG** documents all changes including the known model-divergence
  gap (mde tasks marked complete but per-role model binding was never
  implemented).
2026-06-26 10:05:18 -04:00

1.1 KiB

Adversarial Bug Report: State File Enforcement

Deep Review

The .state file format and transition rules are robust. Approval sub-states create a hard gate that cannot be bypassed via --transition. Atomic writes via tmp+rename prevent corruption on crash.

Potential Issues

  1. Race condition on create: Two concurrent --create-task calls for the same name could both pass the "doesn't exist" check before one creates the directory. The atomic rename pattern mitigates this for .state writes but not for mkdir.

  2. Manual .state tampering: A user or agent could directly edit .state to write an invalid phase name. status.py handles this ("Unknown phase" error), but the error path could be clearer about what phases are valid.

  3. Stale .state after crash: If an agent crashes after producing an artifact but before transitioning .state, the .state lags behind artifacts. The artifact heuristic fallback in --audit Category 2 catches this, but it's a recovery scenario not a normal path.

Verdict: PASS — no security or logic flaws that would compromise enforcement.