[CLAUDE] Docs: S148 — session-model port form hub + /check-email 4 cửa + Sàn-3 dual-accept

Session-model (owner chốt "đối ứng đúng chính xác như hub"):
- Form hub: _context-s-<N>.md (STOCK-map + FLOW append-only + STOCK-touched)
  + _pause-<i>/_tiep-<i> marker 5-trường + _snapshot-<i> + _end (thay closed.md)
- Port /snapshot + scripts/session_scaffold.py (near-verbatim)
  + scripts/session_ctx.py TRIMMED CÓ KHAI (chỉ machine-block + secrets-sweep;
    KHÔNG port jsonl/overhead/cap-getter vì chưa có caller = ghost-wire)
- session-2 migrate sang form hub; session-1 giữ legacy (FROZEN)

Sàn-3 ORPHAN-L:
- DUAL-ACCEPT hub + legacy; glob pause-* KHÔNG khớp _pause-1.md nên không đếm đôi
- VÁ bug có sẵn từ S146: chốt-kết ĐÓNG TRỌN thư-mục (bản cũ c=1 chỉ tha 1 pause,
  lệch chính câu session-end §6.3-bis vẫn nói "mọi pause")
- Fault-inject 10/10 hai chiều + anti-Goodhart

/check-email:
- Wire 4 CỬA phiên (session-start/tiep/session-end/pause), 2 CHẾ-ĐỘ:
  DÒ ~5ms ở cửa dừng-nối (ràng buộc BINDING hub goi-chot §3) ⟂ KÉO ở bookend
- DÒ quét 2 kênh + định tuyến: outbox/se -> /check-email · outbox/all -> /adap-apply
- STAGE-2: 10 thư fan-out verify 2 tuyến 10/10 -> inbox/ai_infra/; backlog root = 0

HANDOFF re-stamp: #1 ĐÓNG (trio đã chạy S144) · #2 đổi trục · #3 anh chốt (a)
+ 4 mục mới (13)-(16); carry #15/#17 đóng, #16 đóng nửa (khai rõ vế còn hở)

H24 tick S147->S148: counter 21->22 CLEAN

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
pqhuy1987
2026-07-24 18:03:16 +07:00
parent 6da7c8898d
commit 24483935cb
23 changed files with 676 additions and 28 deletions

View File

@ -5,6 +5,7 @@ metadata:
node_type: memory
type: feedback
originSessionId: c0d6d8d1-8e0e-46bf-ac36-ab0f45d2629f
modified: 2026-07-24T10:21:02.939Z
---
3 bài học integrity từ S100 H18-adopt (2026-07-02):
@ -15,6 +16,8 @@ metadata:
4. **Sibling-test 2 CHIỀU (S125, 2026-07-16):** mismatch hash có nhánh thứ 3 ngoài tamper/EOL — **VERIFIER của MÌNH hỏng**. Discriminator: chạy verifier trên sibling known-good. Sibling MATCH ⇒ phép đúng, file bệnh (ca S100 frontier-assessment) · sibling CŨNG FAIL ⇒ **verifier bệnh** (ca S125: PS 5.1 `Get-Content -Raw` decode UTF-8-no-BOM bằng ANSI → mojibake → false-TAMPER trên broadcast hub SẠCH; đối chứng `stamp_verify.py` hub → exit-0). Fix gốc: hash CHỈ từ bytes (`ReadAllBytes` + UTF8 decode PIN) — CẤM `Get-Content -Raw` cho hash; đã vá `check-email.md`/`send-email.md` S125.
5. **🔴 Ghost-wire class (c) — CLAIM-OF-FIX: doc khai "đã vá" một kẽ CHƯA vá, và kẽ đó KHÔNG TỒN TẠI ở chỗ nó chỉ (S148, 2026-07-24).** `C14-disposition-per-khoan.md:21` (@S144) khai *"Kẽ đã bịt: `/check-email` bước 2 chỉ đọc `outbox/se`, không nhắc `outbox/all`"*. Lead **tin bản tóm-tắt** → sửa `check-email.md` STAGE 1 đọc thêm `outbox/all`. **Cả hai vế đều sai:** (i) grep `outbox/all check-email.md` = **0 hit** ⇒ chưa hề bịt, chỉ được TUYÊN BỐ; (ii) `outbox/all` **chưa bao giờ** là việc của `/check-email` — 2 kênh 2 tool 2 sổ (`outbox/se``/check-email``_index``outbox/all``/adap-apply`**KHÔNG** vào `_index`, khai ở `_index.md` header dòng 7). Kiểm ngược bằng máy: **22/22** thư `outbox/se` đều có dòng index ⇒ **tool vốn không thủng**. ⇒ lead **vá một tool không hỏng, theo một lời khai không đo**. 🔴 **Kẽ THẬT nằm ở NHỊP, không ở TOOL:** không cửa phiên nào *dò* `outbox/all` ⇒ 10 broadcast fan-out nằm im **5 ngày**. Cùng lượt còn 1 báo-cáo sai cùng gốc: lead khai *"`_index` thiếu 17 dòng"* trong khi cả 17 là fan-out ⇒ **sổ đang đúng**, chỉ là lead áp nhầm luật cho kênh.
**Why:** stamp-then-edit + fabricated-citation là lỗi im lặng — chỉ lộ khi RE-COMPUTE đối chứng nguồn gốc; một làn chỉ kiểm "tóm-tắt trung-thành bản-thô" sẽ mù khi bản-thô bịa từ đầu.
**How to apply:** mọi broadcast/email cross-project → re-compute `SHA256(body)` canonical trước khi áp; mismatch → **sibling-test 2-chiều TRƯỚC**: sibling-fail ⇒ sửa verifier của MÌNH, sibling-match ⇒ HELD + báo nguồn (không suy diễn "chắc CRLF", cũng không hô tamper khi chưa loại trừ tool). Mọi report → chỉ cite run-id/số ĐÃ tồn tại; chưa chạy = placeholder tường minh. Đổi config-consumer → grep key-name toàn scripts/ xem có ai đọc thật không. Liên quan: [[faultinjection-proves-teeth]], [[canonical-spec-over-broadcast]], [[agent-return-garble-recover]].

View File

@ -5,7 +5,7 @@ metadata:
node_type: memory
type: feedback
originSessionId: cc5c42e6-f9aa-404c-adf6-26079c40d118
modified: 2026-07-22T05:34:19.739Z
modified: 2026-07-24T09:10:28.062Z
---
At S50 (2026-06-07 session-end), the 2 INFORM-only monitor subs (tooling-auditor H1 + harvest-curator H2) — briefed **propose-only**, and which **reported "wrote nothing"** — were nonetheless the only plausible authors of ~7 canonical/agent-memory file writes done outside em-main: `error-ledger.md` (2 guard promotions + #57 coords), 3 `adap-reports` (nac→verified-runtime), 4 `agent-memory/*` Recent-activity, and parts of `STATUS.md` (Recently-Done block + In-Progress flip + RAG-line reconcile). mtimes clustered in the 00:0000:05 monitor window. em-main `git diff` at the commit-gate caught every line → all accurate / benign / 0-mojibake / chunk 2415 (no RAG corruption) → adopted per AS-10 keep-if-correct. Logged blameless as **E-006** in the error-ledger.
@ -14,4 +14,6 @@ At S50 (2026-06-07 session-end), the 2 INFORM-only monitor subs (tooling-auditor
**⚠️ S143 (2026-07-22) — premise correction, measured:** the sentence below assumed `Write` had been *removed* from monitor tool-grants, leaving only a Bash residual. **That premise is false at runtime.** Measured on 6 read-only roles (3× `harness-*` trio, 2× H24 auditors, `reviewer`; `tooling-auditor`/`harvest-curator`/`investigator-codebase` same shape): none declare `Write`/`Edit` in their frontmatter `tools:` — yet the **runtime roster still grants `Write, Edit`**, appended at the **end** of the tool list. The tell is positional: `implementer-backend` declares `Edit, Write` at slots 2-3 and its runtime list preserves that file order, so the other six are being **appended at spawn time**, not read from file. ⇒ a frontmatter whitelist is a **statement of intent, not an enforcement mechanism**; "chặn-bằng-thiếu-tool" in any spec is an overclaim (G-015). The residual channel is therefore wider than Bash. Mechanism unknown (hypothesis: `memory: project` needs diary writes — **unverified**, do not assert). Same two-layer shape as [[feedback_permission_grant_two_layers]]: declared-layer ⟂ granted-layer are independent, and verifying one proves nothing about the other. Reported upward in `broadcasts/outbox/ai_infra/2026-07-22-se-to-ai_infra-bao-nac-wave-dot-9-10.md` §3(b).
**How to apply:** Before ANY `/session-end` commit where monitor/sub agents ran, ALWAYS `git status` + `git diff` + chunk-count and **review every non-em-main line** — adopt-if-correct (AS-10) or revert; never blind-commit. If a sub's self-report ("wrote nothing") contradicts git-diff → **Fidelity flag** (escalate reviewer). Recommend to anh/AI_INFRA: harden monitor tool-grant (Write removal leaves Bash residual → consider a hook blocking sub-Bash-write to tracked paths) — but that is a charter-v2 infra decision. Links: [[feedback_store_memory_rebootstrap_protection]] · [[feedback_harness_123_adoption]] · [[feedback_session_end_memory_write_verify]].
**🔴 S148 (2026-07-24) — RE-MEASURED live, count is 15 not 6:** the "6 roles" above was an S143-era undercount (S143 itself already revised it to 9 mid-entry). Fresh count from disk + this session's runtime registry: **20 agent files 5 legitimate write-specialists (`implementer-backend`, `implementer-frontend`, `frontend-designer`, `office-document`, `test-specialist`) = 15 read-only roles that declare NO `Write`/`Edit` in frontmatter `tools:` — and the runtime grants `Write, Edit` to all 15.** Two-sided proof: `.claude/agents/reviewer.md:7` declares `[Read, Grep, Glob, Bash, mcp__rag-unified__*]` while the session's agent listing shows `…, Write, Edit`; `harness-eval`'s own description string says *"KHÔNG store_memory, KHÔNG Write/Edit"* and it is granted both. 🔸 **The number grows with the roster, it is not a worsening condition** — don't read a rising count as a regression. 🔴 **Quote a count here only if you just measured it** — this line has now been wrong twice (6 → 9 → 15) precisely because it was re-cited from memory instead of re-counted.
**How to apply:** Before ANY `/session-end` commit where monitor/sub agents ran, ALWAYS `git status` + `git diff` + chunk-count and **review every non-em-main line** — adopt-if-correct (AS-10) or revert; never blind-commit. If a sub's self-report ("wrote nothing") contradicts git-diff → **Fidelity flag** (escalate reviewer). 🔒 **DO NOT re-propose hardening — anh decided @S148 (2026-07-24): option (a), keep as-is, NO `PreToolUse` hook blocking sub-writes to tracked paths.** So the frontmatter whitelist stays **documentation of intent**, and `git diff` at the commit-gate is the *only* real containment — it catches **after** the write, never **before**. Re-raise only if anh reopens it or the hub returns a mechanism answer (`[carry:tools-whitelist-no-teeth]` is now narrowed to the hub-confirmation leg alone). Anh's framing was *"có j audit sau"* — accept the residual risk now, catch it in audit later; that is a deliberate trade, not an oversight to fix behind his back. Links: [[feedback_store_memory_rebootstrap_protection]] · [[feedback_harness_123_adoption]] · [[feedback_session_end_memory_write_verify]].