From 3a394b02cc3cdbdeca3deff0519f59ba6ae81bd8 Mon Sep 17 00:00:00 2001 From: pqhuy1987 Date: Sat, 18 Jul 2026 01:00:30 +0700 Subject: [PATCH] wal: pause --- .claude/WAL.md | 30 +-- .claude/agents/reviewer.md | 2 +- .claude/commands/pause.md | 3 +- .claude/commands/session-end.md | 11 +- .claude/commands/session-start.md | 10 + .claude/commands/tiep.md | 4 + .claude/governance/.session-counter.json | 11 +- docs/governance/error-ledger.md | 2 + docs/rules.md | 1 + scripts/governance-detectors.ps1 | 260 +++++++++++++++++++++++ 10 files changed, 313 insertions(+), 21 deletions(-) diff --git a/.claude/WAL.md b/.claude/WAL.md index 068ff21..967f02c 100644 --- a/.claude/WAL.md +++ b/.claude/WAL.md @@ -1,21 +1,21 @@ # WAL — auto-generated, không sửa tay -updated: 2026-07-17 (S139 — /tiep resume: verify 6/6 KHỚP, tick 12→13 [ancestor FAIL-LOUD lần 3 cùng class S127/S133 — báo anh], relaunch Invocation 3) | session: S139 | branch: main -goal: Wave adap 3 bản AI_INFRA 17-07 (đính-chính-kép `624c378d` · master-checklist `cadd24ae` · năm-quyết `123d8272`) — pipeline anh: check-email → invest Fable → spec → review Fable → hmw implement Opus MAX → L3 review + reports + STAGE-2 + email hub. (Đầu phiên: closeout-S137 đã trả + push `d99de8f`.) +updated: 2026-07-18 00:59 (S139 — /pause GIỮA L3-review wave adap 3 bản; tick 3.5 = NO-OP đúng contract, cùng nhãn-phiên S139) | session: S139 | branch: main +goal: Wave adap 3 bản AI_INFRA 17-07 (đính-chính-kép `624c378d` · master-checklist `cadd24ae` · năm-quyết `123d8272`) — implement XONG-VERIFIED, còn: L3 verdict → đóng run → adap-reports ×3 → STAGE-2 → email hub → commit/push. chain: -[x] 1. STAGE-1 check-email: 3 bản copy verbatim + verify 2-tuyến WHOLE+BODY 3/3 + _index 3 row pending — commit `efc0828` (verify: ls broadcasts/inbox/*.md = 3 file + README) -[x] 2. invest Fable `wf_56d248ea-f8e` CLEAN — `sub-investigator-codebase-0.md` 30.867B; 3/3 FIT, cần-implement = 3 cụm; Δ2 SE-originated; lead verify 4/4 claim; harvest C4 diary inv-cb APPENDED (hook-cap bắn ~24.1KB — carry mở, KHÔNG tự nén) -[x] 3. review Fable `wf_a0aa62f5-9e8` **#53-GARBLE** trước verdict → ladder: disk✗ · journal✗ · SendMessage✗ ("No transcript found" — wf-agent KHÔNG resume được) · transcript-forensics✓ → **em-main-solo gate GO_WITH_FIXES 3M/3m/1n** → spec **v2** + `review-synthesis.md` trên đĩa; reviewer diary entry ON-BEHALF appended @pause -[x] 4. wf: hmw-implement-spec-v2 runId=wf_f9981ae5-903 (relaunch @S139) **XONG done=2/2 VERIFIED** — L1 CLEAN PASS 6/6 (sub-0.md; MASTER-CHECKLIST 4/4 · heading 26/28/7/14 bất-biến · config-token 10/10) · L2 #53-garble → em-main disk-truth: +260/0 add-only, fault-inject 13/13 (C6 7/7 lane + H24-4 6/6 em-main hoàn tất sau harness-bug $h/$H), live TOTAL 45 giữ + 0-flag 2-net + exit-0 + ASCII-0 (sub-1.md ON-BEHALF) · harvested=C4 diary appended -[!] 5. wf: L3-review runId=wf_65e5cf1e-397 ĐANG CHẠY NỀN — EM micro-edits ×4 ĐÃ LAND TRƯỚC L3 (đảo footer-v1 theo fix m-3 no-self-exempt, khai trong report: reviewer.md:46 +grounded · K4 rules §6.6 + trỏ G-011 · error-ledger +G-011-ladder-canonical +K6.2-re-base; EM tự-bắt-tự-sửa 1 lỗi 4-cấp-mark khi edit — L3 được lệnh re-verify). Còn SAU L3-GO: scribe sub-reviewer-0.md + implement-synthesis.md + adap-reports ×3 + STAGE-2 move + _index processed + email hub + commit/push (§5.0/§5.2) +[x] 1. STAGE-1 check-email 3 bản verify 2-tuyến 3/3 — commit `efc0828` (ls broadcasts/inbox/*.md = 3 file + README) +[x] 2. invest Fable `wf_56d248ea-f8e` CLEAN — `sub-investigator-codebase-0.md` 30.867B; lead verify 4/4 claim +[x] 3. review Fable `wf_a0aa62f5-9e8` #53-garble → em-main-solo gate GO_WITH_FIXES 3M/3m/1n → spec **v2** + `review-synthesis.md` trên đĩa +[x] 4. hmw-implement relaunch @S139 `wf_f9981ae5-903` XONG done=2/2 VERIFIED — L1 PASS 6/6 (sub-0.md; heading 26/28/7/14 bất-biến · config-token 10/10) · L2 #53-garble → em-main disk-truth: +260/0, fault-inject **13/13** (C6 7/7 lane · H24-4 6/6 em-main hoàn tất sau harness-bug $h/$H), live TOTAL 45 giữ + 2-net 0-flag + exit-0 + ASCII-0 (sub-1.md ON-BEHALF) · diary C4 appended · 4 micro-edits EM land (reviewer.md +grounded · rules §6.6 K4 · error-ledger +G-011-canonical +K6.2-re-base; EM tự-bắt-sửa lỗi 4-cấp-mark) · 🔴 TOÀN BỘ diff wave nằm TRONG commit `wal: pause` này (đối-chứng: git diff 8202374..HEAD --stat) +[!] 5. wf: L3-review run=2026-07-17-S138-adap-3-ban-17-07 runId=wf_65e5cf1e-397 args={1-lane reviewer read-only: falsify acceptance L1/L2 (re-đo grep/heading + re-run scratchpad faultinject.ps1 byte-exact + live-run) + chấm 4 micro-edits EM m-3 no-self-exempt (re-verify chỗ 4-cấp-mark) + đánh-giá quyết-định đảo-thứ-tự micro-edits-trước-L3 + vocab-note 'Luật-số sàn-5(S138)' vs 'Sàn-5 H22' cùng file session-end + measured-label gate + add-only-floor; VERDICT dòng-1 findings} done=0/1 harvested=no — phóng 00:5x, CHẾT THEO PHIÊN khi thoát → /tiep §4; reviewer read-only 0-vết-đĩa là BÌNH-THƯỜNG, đường vớt = journal + transcript subagents/workflows/wf_65e5cf1e-397/ (cùng máy), mất transcript (khác máy) → relaunch từ script hmw-wf_65e5cf1e-397.js hoặc prompt tương-đương +[ ] 6. Sau L3-GO: scribe sub-reviewer-0.md (EM — reviewer no-Write) → xử fixes nếu có → `implement-synthesis.md` đóng run → adap-reports ×3 (bản-1 kèm evidence Δ2 SE-originated + re-grep 5-nhãn; bản-3 kèm bảng K3 3-hit/3-traced + candidate RỖNG) → STAGE-2 move 3 file + `_index` processed → email hub selftest-stamp → commit/push (§5.0/§5.2) -next: đợi L3 return (garble → disk-truth/transcript-forensics ladder như cũ) → xử fixes nếu có → đóng run (synthesis) → adap-reports ×3 → STAGE-2 → email hub → commit/push. -carry (ANH): 8 mục HANDOFF segment S135-S137 (UAT ×2 · D1 · hook-cap · DP-2 · DP-5 sleep 183KB · close-sweep 7-carry · phép 8) + MFE GOODHART-WARN strikes 21→23 + hook-cap bắn thêm ×2 S138 (inv-cb ~24.1KB + reviewer ~18.2KB sau on-behalf). +next: /tiep → đối-chứng L3: grep '"type":"result"' journal wf_65e5cf1e-397 (path trong verify) — CÓ result = harvest verdict từ journal/transcript + đi tiếp mục 6; KHÔNG = relaunch L3 (1-lane reviewer, args snapshot ở mục 5). +carry (ANH): 1) dangling-head FAIL-LOUD ×3 (S127/S133/S139) chờ anh/hub quyết · 2) đảo-thứ-tự micro-edits-trước-L3 theo m-3 chờ anh OK · + 8 mục HANDOFF segment S135-S137 + MFE GOODHART-WARN strikes 21→23 + hook-cap bắn ×2 S138 (inv-cb ~24.1KB + reviewer ~18.2KB). verify: -- git log --oneline -5 # efc0828 STAGE-1 + d99de8f closeout phía dưới -- ls .claude/workflows/runs/2026-07-17-S138-adap-3-ban-17-07/ # run.md + sub-investigator-codebase-0.md + spec + review-synthesis (+ sub-implementer-backend-* nếu lane kịp ghi) -- git status --porcelain -- .claude/commands/ scripts/governance-detectors.ps1 # edit DỞ của 2 lane (có = lane đã chạy tới đó; /tiep ground-truth thắng) -- grep -m1 "v2 — sau gate" .claude/workflows/runs/2026-07-17-S138-adap-3-ban-17-07/spec-adap-3-ban-17-07-2026.md -- grep -c "pending | (root)" broadcasts/_index.md # = 3 (STAGE-2 CHƯA move) -- grep -m1 "ON-BEHALF" .claude/agent-memory/reviewer/MEMORY.md # entry on-behalf đã append +- git log --oneline -3 # HEAD = wal: pause S139 (chứa TOÀN BỘ diff wave + WAL/counter/diary/sub-MD) +- git diff 8202374..HEAD --stat # 8 file wave: 4 commands + governance-detectors.ps1 + reviewer.md + rules.md + error-ledger.md (+ WAL/counter/MEMORY/sub-MD) +- ls .claude/workflows/runs/2026-07-17-S138-adap-3-ban-17-07/ # 6 file (run/spec/review-synthesis/sub-inv/sub-impl-0/sub-impl-1); sub-reviewer-0.md CHƯA CÓ = L3 chưa scribe (EM scribe sau verdict) +- grep -c "\"type\":\"result\"" "C:/Users/pqhuy/.claude/projects/D--Dropbox-CONG-VIEC-SOLUTION-SOLUTION-ERP/09780401-25c1-438b-9fe5-f3f39ea69a07/subagents/workflows/wf_65e5cf1e-397/journal.jsonl" # ≥1 = L3 kịp trả verdict trước khi phiên chết +- powershell.exe -ExecutionPolicy Bypass -File scripts/governance-detectors.ps1 # exit-0 · TOTAL=45 · C6/H24-4 0-flag count-riêng (re-verify L2 sống) diff --git a/.claude/agents/reviewer.md b/.claude/agents/reviewer.md index 82e7b4d..858411c 100644 --- a/.claude/agents/reviewer.md +++ b/.claude/agents/reviewer.md @@ -43,7 +43,7 @@ Em main spec will include: Apply ALL categories below (Category 6 chỉ khi target gồm nội dung **hướng ra ngoài**: email / adap-report / broadcast / shared-doc): -- **Measured-label gate (sàn-sự-thật 190c11ba):** diff chứa con-số mang nhãn đo-lường (measured/empirical/calibrated/đã-đo)? → hỏi: "phép kiểm nào khiến con số này TRƯỢT nếu nó sai?" Không trả lời được → yêu cầu 1 trong 3: phản-chứng chạy được · miễn-trừ lý-do visible · bỏ nhãn. +- **Measured-label gate (sàn-sự-thật 190c11ba):** diff chứa con-số mang nhãn đo-lường (measured/empirical/calibrated/grounded/đã-đo)? → hỏi: "phép kiểm nào khiến con số này TRƯỢT nếu nó sai?" Không trả lời được → yêu cầu 1 trong 3: phản-chứng chạy được · miễn-trừ lý-do visible · bỏ nhãn. --- diff --git a/.claude/commands/pause.md b/.claude/commands/pause.md index 3001613..905c34c 100644 --- a/.claude/commands/pause.md +++ b/.claude/commands/pause.md @@ -36,12 +36,13 @@ Thực-hiện **tuần-tự 5 bước** sau; trong lúc chạy **KHÔNG nhận v - **KHÔNG push.** (Repo trong Dropbox → thư-mục `.git` được cloud-sync, nên commit local vẫn **durable** qua tắt-máy / đổi-acc.) ## 5. Báo-cáo ngắn rồi DỪNG HẲN -Báo đúng năm ý: +Báo đúng sáu ý: 1. **goal** — mạch việc đang dở là gì. 2. **mục `[!]` đầu-tiên** — bước dở gần nhất. 3. **workflow bỏ lại** (nếu có) — dòng `wf:` đã ghi. 4. "**an-toàn để thoát, đổi acc, hoặc tắt máy**". 5. **dòng-nợ (Item 2 S135):** gọi `powershell.exe -ExecutionPolicy Bypass -File scripts/nhip-no-probe.ps1` in dòng-nợ 3-vế (nhịp-kiểm đọc post-tick bước 3.5). 🔴 **probe KHÔNG chặn điểm dừng**: lỗi → in `probe-loi (khong chan)` → đi tiếp, VẪN tuyên-bố "an-toàn để thoát". +6. **🧾 MASTER-CHECKLIST rút-gọn (S138):** derive từ WAL vừa ghi (bước 3) + HANDOFF — in **Tầng-1** mỗi arc 1 dòng `{đóng · đang · chưa}` + **đếm 4-nhóm** (`xong` / `đang-dở` / `chờ-anh` / `chưa-làm`) + **liệt nhóm chờ-anh — 🔢 BẮT BUỘC ĐÁNH SỐ** (anh trả lời bằng số). 🔴 **Checklist = VIEW derive tươi — CẤM tạo file checklist nguồn-đôi (sàn-3).** Rồi **DỪNG HẲN**, KHÔNG nhận việc mới. diff --git a/.claude/commands/session-end.md b/.claude/commands/session-end.md index 611ee2c..ee18586 100644 --- a/.claude/commands/session-end.md +++ b/.claude/commands/session-end.md @@ -53,12 +53,14 @@ Em main PHẢI echo **TOÀN BỘ nội dung command body này** (đầy đủ Ph > 🔸 *Nhãn cũ ghi "8-step" trong khi thân đã có (a)→(i) = 9 — `view-stale-count` điển-hình, vá @S122 khi thêm (j). Từ nay **KHÔNG chép số** vào nhãn: đếm từ thân (B1).* - **(a) summary-index** += 1 dòng/session vào `STATUS.md` Recently Done (pointer, KHÔNG full-log). - **(b) Active-Guards** (error-ledger): promote guard **2-strike** (episodic→procedural) · mark `verified` nếu held qua session · retire theo **net-effect** (hại>lợi → gỡ). -- **(c) chore-flag:** agent L1 >~30KB → archive L2 · error-ledger open-entry quá ngưỡng · **0-byte memory check (AS-8)** · **🌙 sleep-check (Harness-10b, S72):** `last_sleep_at` null hoặc ≥7d (`memory-budget.json`) → INFORM gợi-ý `/sleep-recovery-memory-l2` (KHÔNG auto-run) **+ byte-display (Item 8/M-10 S135):** khi INFORM fire → in kèm **tổng byte `agent-memory/*/archive/.md` CHƯA có `.gist.md`** (match PREFIX kỳ, đo TƯƠI `(Get-Item).Length` — 🔴 CẤM `Get-Content`-đếm, bẫy encoding E-010; baseline 17-07 kỳ `2026-07` ≈183KB/5 file) → anh đặt ngưỡng byte sau, 🔴 **KHÔNG bịa số** (giữ INFORM 7-ngày — DP-5 quyền owner cục-bộ) · **🗜️ Harness-11 A/D2 (S75):** chạy `powershell.exe -ExecutionPolicy Bypass -File scripts/memory-archive-gate.ps1` (DRY-RUN) → đề-xuất dồn-archive sub over-cap (A4 hysteresis 0.85 + A5 keep-floor 5 + A6 2-strike) + A7 NO-API L1-eval (pointer-resolve + byte-0-loss). Engine → [`docs/governance/harness-11-engine.md`](../../docs/governance/harness-11-engine.md). DRY-RUN báo kế-hoạch; MOVE thật do em-main (D5 AUTO semantic-null sau khi xem). · **📊 Hot-feed %-print CUỐI phiên (Harness-15-v2 §G.4, S82):** in composition Tầng-1 theo **%/4-bucket** SAU khi đã nạp/tăng trong phiên + **Headroom còn-trống** so cap role (`token_governor.tier1_hotfeed_tokens`). Đối-xứng `session-start §2.1.6` (đầu phiên). Mục-đích: anh thấy Tầng-1 phình/teo ra sao + còn trống bao nhiêu → quyết chỉnh cap. 🔴 con-số = quyền anh (chủ-dự-án); em-main chỉ báo-%, KHÔNG tự-chỉnh. · **📊 Bảng-số ngân-sách + run-loop 2-tầng (M.B/M.C — Harness-20 adap S103, [`engine §M`](../../docs/governance/harness-11-engine.md)):** chạy `powershell.exe -ExecutionPolicy Bypass -File scripts/crystallized-backfill.ps1` → in BẢNG số THẬT (cap/hotload-bytes/tok-RANGE/headroom/target/backfill, live 0-hardcode) cạnh %-print. **Tầng-1 ĐO** (deterministic scripts) mỗi end = khối-số tươi (chống "khai-chạy-mà-không-chạy"); **Tầng-2 TINH-CHỈNH on-signal** (gap-mới/drift-vs-last/orphan-TĂNG/coverage-tụt → **cảnh-báo ĐỎ** + refine-in-session HOẶC carry-hi-prio nếu đứt-phiên) — KHÔNG nuốt tín-hiệu; weekly full-refine backstop. backfill default 0=OFF (owner). 🟡 M.C largely-already-met (H17-loop + %-print đã có ở dưới), khối-số = formalize. · **🧪 MFE retention opt-in (Harness-16 §H):** lệnh kèm `eval` → chạy `scripts/mfe-eval.ps1` cuối-phiên (retention; chênh vs baseline §2.1.6 = rot trong-phiên) → quyết-định 2-ca: **thiếu-chỗ→TĂNG budget** (anh quyết) / **rot→SẮP-XẾP-LẠI** (ưu-tiên-giá-trị). READS budget, KHÔNG ghi/auto-tune. · **🔁 H17 loop-REFINE (§I, S95 — [`harness-11-engine.md §I`](../../docs/governance/harness-11-engine.md)):** lệnh kèm `eval` → chạy thêm `scripts/memory-selfimprove-audit.ps1` (spec-audit CRITERIA+GAP) → áp bảng B1 **tín-hiệu→hành-động**: floor-rot→**reinject-verbatim** (ghi [`reinject-ledger.md`](../governance/reinject-ledger.md) CG-1 ≤1/N=3; đo-lại vẫn thiếu→**escalate anh** KHÔNG tự-reinject-lần-2) · repeat≥2→promote · old+valueless→archive-gate · raw→distill (`/sleep-recovery-memory-l2`). Phân-loại B3 (build-gap vs floor-rot) TRƯỚC reinject. em-main single-writer D9; loop CHỈ đề-xuất (D6). Light→skip. +- **(c) chore-flag:** 🔒 **Đóng-băng bề-mặt-đo (C1 — 2 câu, S138):** "Từ lúc chạy script đo đầu-tiên của khối (c) tới verdict cuối: KHÔNG ghi vào **bề-mặt-đo** = `.claude/agent-memory/**` + `.claude/governance/{.session-counter.json, ACTIVE-MARKS.md}` + `docs/{STATUS,HANDOFF,gotchas}.md` + `docs/governance/error-ledger.md` + `docs/changelog/migration-todos.md` + `.claude/agents/*.md` + `runs/*/run.md`; việc ghi phát sinh giữa chừng → xếp hàng SAU verdict. Ngoại-lệ: `.claude/WAL.md` (ngoài vùng đọc cả 5 script đo) + state-write của chính bộ-đo (`.mfe-state.json`)." · agent L1 >~30KB → archive L2 · error-ledger open-entry quá ngưỡng · **0-byte memory check (AS-8)** · **🌙 sleep-check (Harness-10b, S72):** `last_sleep_at` null hoặc ≥7d (`memory-budget.json`) → INFORM gợi-ý `/sleep-recovery-memory-l2` (KHÔNG auto-run) **+ byte-display (Item 8/M-10 S135):** khi INFORM fire → in kèm **tổng byte `agent-memory/*/archive/.md` CHƯA có `.gist.md`** (match PREFIX kỳ, đo TƯƠI `(Get-Item).Length` — 🔴 CẤM `Get-Content`-đếm, bẫy encoding E-010; baseline 17-07 kỳ `2026-07` ≈183KB/5 file) → anh đặt ngưỡng byte sau, 🔴 **KHÔNG bịa số** (giữ INFORM 7-ngày — DP-5 quyền owner cục-bộ) · **🗜️ Harness-11 A/D2 (S75):** chạy `powershell.exe -ExecutionPolicy Bypass -File scripts/memory-archive-gate.ps1` (DRY-RUN) → đề-xuất dồn-archive sub over-cap (A4 hysteresis 0.85 + A5 keep-floor 5 + A6 2-strike) + A7 NO-API L1-eval (pointer-resolve + byte-0-loss). Engine → [`docs/governance/harness-11-engine.md`](../../docs/governance/harness-11-engine.md). DRY-RUN báo kế-hoạch; MOVE thật do em-main (D5 AUTO semantic-null sau khi xem). · **📊 Hot-feed %-print CUỐI phiên (Harness-15-v2 §G.4, S82):** in composition Tầng-1 theo **%/4-bucket** SAU khi đã nạp/tăng trong phiên + **Headroom còn-trống** so cap role (`token_governor.tier1_hotfeed_tokens`). Đối-xứng `session-start §2.1.6` (đầu phiên). Mục-đích: anh thấy Tầng-1 phình/teo ra sao + còn trống bao nhiêu → quyết chỉnh cap. 🔴 con-số = quyền anh (chủ-dự-án); em-main chỉ báo-%, KHÔNG tự-chỉnh. · **📊 Bảng-số ngân-sách + run-loop 2-tầng (M.B/M.C — Harness-20 adap S103, [`engine §M`](../../docs/governance/harness-11-engine.md)):** chạy `powershell.exe -ExecutionPolicy Bypass -File scripts/crystallized-backfill.ps1` → in BẢNG số THẬT (cap/hotload-bytes/tok-RANGE/headroom/target/backfill, live 0-hardcode) cạnh %-print. **Tầng-1 ĐO** (deterministic scripts) mỗi end = khối-số tươi (chống "khai-chạy-mà-không-chạy"); **Tầng-2 TINH-CHỈNH on-signal** (gap-mới/drift-vs-last/orphan-TĂNG/coverage-tụt → **cảnh-báo ĐỎ** + refine-in-session HOẶC carry-hi-prio nếu đứt-phiên) — KHÔNG nuốt tín-hiệu; weekly full-refine backstop. backfill default 0=OFF (owner). 🟡 M.C largely-already-met (H17-loop + %-print đã có ở dưới), khối-số = formalize. · **🧪 MFE retention opt-in (Harness-16 §H):** lệnh kèm `eval` → chạy `scripts/mfe-eval.ps1` cuối-phiên (retention; chênh vs baseline §2.1.6 = rot trong-phiên) → quyết-định 2-ca: **thiếu-chỗ→TĂNG budget** (anh quyết) / **rot→SẮP-XẾP-LẠI** (ưu-tiên-giá-trị). READS budget, KHÔNG ghi/auto-tune. · **🔁 H17 loop-REFINE (§I, S95 — [`harness-11-engine.md §I`](../../docs/governance/harness-11-engine.md)):** lệnh kèm `eval` → chạy thêm `scripts/memory-selfimprove-audit.ps1` (spec-audit CRITERIA+GAP) → áp bảng B1 **tín-hiệu→hành-động**: floor-rot→**reinject-verbatim** (ghi [`reinject-ledger.md`](../governance/reinject-ledger.md) CG-1 ≤1/N=3; đo-lại vẫn thiếu→**escalate anh** KHÔNG tự-reinject-lần-2) · repeat≥2→promote · old+valueless→archive-gate · raw→distill (`/sleep-recovery-memory-l2`). Phân-loại B3 (build-gap vs floor-rot) TRƯỚC reinject. em-main single-writer D9; loop CHỈ đề-xuất (D6). Light→skip. - **🧬 memory-triple artifact (Item 3-bis S135 — B2 vòng-3 lên CHỨC-NĂNG; 0 vai mới, 0 script mới):** khi chạy khối (c) memory-maintenance ở trên, ghi **3 dòng artifact tuần-tự** (prefix `memory-triple`) vào session-log (`docs/changelog/sessions/`) — run-record 3-stage đo→đề-xuất→kiểm: ``` memory-triple: do= memory-triple: de-xuat= memory-triple: kiem= + memory-triple: do-record= + memory-triple: do-record= ``` - **(d) flush agent-memory** mỗi sub đã spawn session này — **spawn-record 4-field** `{agent · task · nấc(agreed/executed/verified) · evidence}`. (0 sub spawn → "n-a".) → **⬜ harvest-curator (H2) HỖ TRỢ:** spawn → propose spawn-record cho mọi sub đã chạy → em main single-writer VERIFY → APPEND (B3 no-overwrite-unverified). - **(e) pending-request audit:** request anh CHƯA-thực-thi đã log SPECIFICS chưa (KHÔNG placeholder). @@ -103,6 +105,7 @@ Em main PHẢI echo **TOÀN BỘ nội dung command body này** (đầy đủ Ph **Vì sao bắt buộc:** carry-age detector đo **streak** = số segment LIÊN-TỤC mang cùng slug. Đo thật @S121: **45 logic-segment nhưng `carry-lines=1`** ⇒ streak **luôn ≡ 1** ⇒ **0 fire VĨNH VIỄN, kể cả sau W2**. Bằng-chứng: `tra-bui-relogin` chỉ đóng dấu **seg#0 (S119)**, trong khi **seg#2 (S118)** nhắc **đúng việc đó** mà **không có dấu** ⇒ **tuổi thật ≥2, máy đọc 1**. ⇒ detector **vacuous về CẤU-TRÚC**, không phải sai ngưỡng. 🔴 **Không retrofit dấu vào segment CŨ** (§Q3 no-retrofit) ⇒ **đường DUY NHẤT còn lại** = re-stamp từ nay về sau; tuổi sẽ đo đúng **từ S122 trở đi**, và **khai thẳng** rằng carry mở trước S122 có tuổi **đo-thiếu**. **Định-nghĩa "dòng-carry" (owner O3):** = **đoạn LOGIC** `NEXT anh` / `NEXT em` trong mega-line — KHÔNG phải dòng vật-lý. ⚠️ Bẫy đếm: `grep -c` đếm **DÒNG** (=1 trên mega-line), `grep -o | wc -l` đếm **occurrence** (=n). Dùng đúng cái thứ hai. + 🔢 **Luật-số sàn-5 (S138):** khối **chờ-anh** trong `HANDOFF` LUÔN **đánh số** (anh trả lời bằng số) — khớp nhóm-3 MASTER-CHECKLIST + nghi-thức re-stamp carry ở trên; số cố-định giúp anh trả lời gọn. - **(v) 🔷 TICK-at-close (Item 1(d) S135 — idempotent):** tick `.claude/governance/.session-counter.json` **theo contract** — 🔴 **CON-TRỎ `session-start §2.1.8`, CẤM chép logic tick** (B1). Idempotent: cùng nhãn-phiên phiên này ⇒ **NO-OP** (nếu `/session-start` hoặc `/tiep` đã tick nhãn này). Có delta → **§5.1 add đích-danh counter-file** (file ngoài hook-3-path; bằng-chứng sống: tick S133 nằm uncommitted qua 2 closeout liên tiếp — M-7). - **(vi) 🔥 Force-fire bù khi closeout gộp sổ (Item 3 S135 — floor B1 §3.2):** đếm `P` = số `wal: pause` gộp vào closeout này: `P=$(git log --format=%s "..HEAD" | grep -c '^wal: pause' || true)` — `` = commit gần nhất match **regex closeout DÙNG CHUNG Item 4** `^\[CLAUDE\] Docs: S\d+.*(closeout|session-end)` (1 regex, đừng chép 2 bản). 🔴 **so-sánh SỐ, KHÔNG dùng exit-code** (`grep -c` trả exit 1 khi đếm 0 — §5.0 (a)): `[ "$P" -ge 1 ]`. Nếu **`P >= 1` HOẶC** nhãn đóng dạng `S-S` (closeout gộp nhiều phiên) ⇒ coi như **`OVERDUE(light)` bất-kể counter** → in dòng-nợ (qua (i)) + **INFORM-BẮT-BUỘC** anh + **đề-xuất spawn cặp H24 (`lead-view-auditor` + `lead-omission-auditor`) NGAY closeout này**. 🔴 **DP-3 consent-gate GIỮ** (luật owner-era §L.b(j)(ii) + `session-start §2.1.8(e)` "KHÔNG auto-run — anh consent" + hẹn hub "light-run owner-triggered"): force-fire = INFORM-bắt-buộc + đề-xuất-chạy mặc-định, **anh gật mới chạy trong closeout**. Báo hub SELF-CHECK ô3 = **"PASS-với-carve-out (consent)"**, KHÔNG PASS trần. - **(g) 🔌 tooling-freshness CHỐT (🟫 tooling-auditor H1 — Harness 1):** spawn → chốt 4-mặt (skill·sub-role·plugin·docs) đổi gì session này + **new-alloc audit** (skill/plugin MỚI chưa phân-bổ → đề-xuất gán em main + sub phù-hợp vai) + flag doc-drift/roster-lệch/count-stale. Propose → em main APPEND/sửa doc (single-writer). 🔴 G-015: 2 monitor = propose-only, em main VERIFY trước APPEND (Bash residual → KHÔNG "read-only enforced"). @@ -158,6 +161,12 @@ Plan cha: [tên] - 🟩 cicd-monitor — [g] - 👤 chủ trì — [h] ``` +> 🧾 **MASTER-CHECKLIST — "TỔNG-HỢP CHỐT" (VIEW derive tươi từ WAL · STATUS · HANDOFF · ACTIVE-MARKS; KHÔNG file nguồn):** +> - **Tầng-1** — mỗi arc/đầu-việc-lớn **1 dòng** `{đóng · đang · chưa}`; nêu rõ **arc nào ĐÓNG trong phiên này**. +> - **Tầng-2 — 4 nhóm:** 1) **xong** (WAL `[x]` + Recently-Done) · 2) **đang-dở + breakdown** (đã-xong / đang-giữa / còn-gì) · 3) **chờ-anh — 🔢 BẮT BUỘC ĐÁNH SỐ** (HANDOFF NEXT-anh + ⚑ pending + mark treo) · 4) **chưa-làm / hẹn-cuối-phiên** (WAL `[ ]` + NEXT-em). +> - 🔻 **MỌI mục chưa-đóng PHẢI chỉ đích nơi đổ:** carry-slug `HANDOFF` / `WAL`-line / `STATUS`-row — không mục nào rơi khỏi sổ. +> 🔴 **Checklist = VIEW derive tươi — CẤM tạo file checklist nguồn-đôi (sàn-3).** + ### SOLUTION_ERP report (per-session) - Tóm tắt việc done + commit SHA + CI Run verdict + bundle hash rotate + plan progress - (SE KHÔNG copy phần "6 sister report" của AI_INFRA host) diff --git a/.claude/commands/session-start.md b/.claude/commands/session-start.md index 2dc009d..6ace27a 100644 --- a/.claude/commands/session-start.md +++ b/.claude/commands/session-start.md @@ -132,6 +132,7 @@ Em main đọc `.claude/WAL.md` (sổ mạch-việc-dở H22 — ghi-đè ≤40 - Đọc `.claude/agent-memory/memory-budget.json` → so kích-thước THẬT `_INDEX.md` mỗi sub vs cap. Nếu cắt-cho-vừa-ngân-sách đang rớt dấu-mốc quan trọng → **bump budget** (chốt-chặn chống "quên chỉnh ngân sách"). Đo lại bằng `scripts/measure-agent-memory.ps1` (seed-by-measure — KHÔNG đặt cap bằng số tưởng tượng). - L1 over-cap → curate L1→L2 (byte-exact additive) + build/refresh `_INDEX.md` (con-trỏ **substring** sha-keyed, fallback Ctrl-F) + `.gist.md` (nén 4-field, `distill-gen` counter, verbatim FROZEN). Rollout đầu: 4 over-cap sub (S70). +- 🔒 **Mirror C1 — bề-mặt-đo đóng-băng (S138):** trong CỬA-SỔ đo (từ script đo đầu-tiên tới verdict cuối) KHÔNG ghi **bề-mặt-đo** (agent-memory · `.session-counter.json` · ACTIVE-MARKS · STATUS · HANDOFF · gotchas · error-ledger · migration-todos · `agents/*.md`); ngoại-lệ `.claude/WAL.md` + `.mfe-state.json`. 🔴 Danh-sách VERBATIM đầy-đủ = canonical ở `session-end.md §L.b(c)` (B1 — bước này CHỈ mirror ngắn). ### 2.1.3 Harness-11 D1 — DÒ+BÁO governance-detectors (2026-06-18 S75) @@ -253,6 +254,15 @@ Plan cha: [tên] - 👤 chủ trì — phụ trách [h] ``` +> 🧾 **MASTER-CHECKLIST (khuôn CHUNG — VIEW derive tươi từ WAL · STATUS · HANDOFF · ACTIVE-MARKS; KHÔNG file nguồn):** in KÈM work-state §2.1.5 (GIỮ NGUYÊN làm NGUỒN — REPORT trỏ nó, KHÔNG nhân-bản). +> - **Tầng-1** — mỗi arc/đầu-việc-lớn **1 dòng** `{đóng · đang · chưa}` (nguồn: `STATUS.md` Phase-line + Plan cha/con + WAL `goal`). +> - **Tầng-2 — 4 nhóm:** +> 1. **xong** — WAL `[x]` + Recently-Done phiên này. +> 2. **đang-dở + breakdown** (đã-xong-gì / đang-giữa-gì / còn-gì) — WAL `[!]` + chain evidence. +> 3. **chờ-anh — 🔢 BẮT BUỘC ĐÁNH SỐ (anh trả lời bằng số)** — HANDOFF NEXT-anh + ⚑ pending-decisions + mark treo. +> 4. **chưa-làm / hẹn-cuối-phiên (tách từng khoản)** — WAL `[ ]` + NEXT-em. +> 🔴 **Checklist = VIEW derive tươi — CẤM tạo file checklist nguồn-đôi (sàn-3).** + ### SOLUTION_ERP report - Trạng thái spawn TOÀN roster (idle/working) + agentId reuse-able trong session · **+ 1 dòng H24 cadence** (§2.1.8) - Plan progress: ✅ Phase 10 COMPLETE 11/11 · ⬜ Phase 11 polish (wire ApproveV2 skeleton) · 🚫 Phase 9 Ops (anh main coordinate) diff --git a/.claude/commands/tiep.md b/.claude/commands/tiep.md index 9422f79..76919ea 100644 --- a/.claude/commands/tiep.md +++ b/.claude/commands/tiep.md @@ -115,6 +115,10 @@ Tín-hiệu **YẾU NHẤT**, dùng cuối. 🔴 **`porcelain` rỗng KHÔNG ph - **LỆCH** (kết-quả `verify:` / `git status` mâu-thuẫn `chain:`) → **TIN GROUND-TRUTH**: sửa WAL cho khớp thực-tế, **báo chỗ lệch** cho user, RỒI MỚI chạy tiếp. KHÔNG mù-quáng chạy theo chain sai. - **KHỚP** → thực-thi từ **`next:`**, nối chain theo thứ-tự các mục còn `[!]` / `[ ]`. +> **§3-bis — 🧾 in MASTER-CHECKLIST (cập-nhật từ WAL đã reconcile ở §3; VIEW derive tươi, KHÔNG file nguồn):** derive từ WAL (đã ground-truth-reconcile) + HANDOFF — +> - **vừa-xong** (mục vừa chuyển `[!]`→`[x]` khi reconcile) · **vẫn-treo** (`[!]` / `[ ]` còn lại) · **chờ-anh — 🔢 BẮT BUỘC ĐÁNH SỐ** (anh trả lời bằng số). +> 🔴 **Checklist = VIEW derive tươi — CẤM tạo file checklist nguồn-đôi (sàn-3).** + ## 4. Mục `[!]` dạng `wf:` → nhánh recovery-workflow Nếu mục dở là một dòng `wf:` (chết giữa workflow) → relaunch **ĐÃ-CẮT-GỌT**, KHÔNG chạy lại từ đầu: 1. Đọc **run-folder** + `## taskList snapshot` trong `run.md` (danh-sách-task + nội-dung spec đã snapshot lúc phóng). diff --git a/.claude/governance/.session-counter.json b/.claude/governance/.session-counter.json index eed6ee8..9715404 100644 --- a/.claude/governance/.session-counter.json +++ b/.claude/governance/.session-counter.json @@ -10,9 +10,9 @@ "writer": "Lead is single-writer. Wired at /session-start (W3 owns the ritual; W2 owns this file + its shape)." }, "_seed_honesty": "Seeded UNTICKED on purpose. counter=0 and last_ticked_* = null mean 'no tick has ever happened', which is the truth at S121 - the ritual that performs the tick lands in W3. Seeding a fake first tick here would make the very first cadence reading a lie, and H24 exists to catch exactly that kind of invented number.", - "counter": 12, - "last_ticked_session": "S138", - "last_ticked_head": "36e79da4ce89b39bf22ff78e70753c82a03946fc", + "counter": 13, + "last_ticked_session": "S139", + "last_ticked_head": "82023745648f02056d89d4190d1c236b04779b5d", "last_ticked_at": "2026-07-17", "last_audit": { "light_at_counter": 11, @@ -34,6 +34,11 @@ "session": "S133", "event": "ancestor-check FAIL-LOUD lan 2 (cung class S127, dung contract): last_ticked_head 882e0d7 (tick @S131) la dangling commit - object ton tai (cat-file -t = commit) nhung khong reachable tu HEAD. Root-cause: closeout S131-S132 SQUASH wal:-commit (squash->count->push) nen head luc tick bi squash khoi lich su. KHONG phai tamper: counter khong lui (7), file khong sua tay. Xu ly: tick tiep 7->8 CO VET (entry nay) + bao anh trong turn S133. Candidate fix VAN treo cho anh/hub quyet (chua doi contract): chap nhan dangling-object-exists lam bang-chung yeu khi counter khong lui." }, + { + "at": "2026-07-17", + "session": "S139", + "event": "ancestor-check FAIL-LOUD lan 3 (cung class S127/S133, dung contract): last_ticked_head 36e79da (tick @S138 session-start) la dangling commit - object ton tai (cat-file -t = commit) nhung khong reachable tu HEAD 8202374. Root-cause quen thuoc: closeout-S137 chay TRONG phien S138 SAU tick -> squash wal:-commit khien head-luc-tick roi khoi lich su. KHONG phai tamper: counter khong lui (12), file khong sua tay. Xu ly: tick tiep 12->13 CO VET (entry nay) + bao anh trong turn S139 (/tiep resume S138 wave adap-3-ban). Candidate fix [carry:dangling-head] van treo cho anh/hub quyet (da thanh carry named @closeout S137)." + }, { "at": "2026-07-17", "session": "S137", diff --git a/docs/governance/error-ledger.md b/docs/governance/error-ledger.md index 2dfa51a..4cc1bcc 100644 --- a/docs/governance/error-ledger.md +++ b/docs/governance/error-ledger.md @@ -38,6 +38,8 @@ Detect by **action-signature** (NOT "AI tự phán có vi phạm không"). Scan ## 🛡️ Active-Guards index (2-strike promote: episodic → procedural) > **net-effect rule:** a guard that costs more than it saves (hại>lợi) → **retire**. `verified` = ran ≥1× and held. `strikes` = times the underlying error recurred before the guard. +> **G-011 ladder (canonical on-disk từ S139 — trước đó chỉ sống trong lineage adap-reports):** nấc tiến-độ khi khai một việc: `agreed` (đồng-ý làm) → `executed` (lệnh đã chạy xong) → `verified` / `verified-pending-restart` (đã KIỂM chạy thật; edit agent-file no-hot-reload = verified-pending-restart). 🔴 **KHÔNG tự khai `verified`** khi chưa có phép kiểm chạy được. Tham-chiếu: rules §6.6 K4 relay-attribution. +> **Luật re-base số-sống (K6.2 — generalize E-010, adopt S139):** Re-base baseline = chốt số **SỐNG** tại lúc re-base — mọi số vào sổ đọc lại từ **nguồn sống tại thời-điểm ghi** (CẤM chép từ ghi-chú/phiên trước, kể cả ghi-chú của chính mình); byte = `(Get-Item).Length` (E-010). *(nhà đề-xuất-mặc-định — [owner-reviewable])* | Guard | Counters | Tier | Strikes | Verified | Net | |---|---|---|---|---|---| diff --git a/docs/rules.md b/docs/rules.md index aae4137..b5cfa88 100644 --- a/docs/rules.md +++ b/docs/rules.md @@ -399,6 +399,7 @@ Co-Authored-By: Claude Opus 4.8 (1M) # / mã `RC-*` / quote nguyên văn); verb-durable trần = tự-phán. Nấc tiến-độ khi thuật việc → **G-011 ladder** (canonical: [`error-ledger.md`](governance/error-ledger.md) Active-Guards — agreed / executed / verified-pending; KHÔNG tự khai verified). Ranh máy-kiểm nếu mai port scanner lớp-từ: token-attribution **cùng dòng** + matcher PHẢI `Test-Quoted`. *(nhà đề-xuất-mặc-định — [owner-reviewable], anh đổi nhà sang error-ledger được khi đọc report)* ## 7. Testing (Phase 9 active — 77 test pass post-Mig 21 + CI gate live) diff --git a/scripts/governance-detectors.ps1 b/scripts/governance-detectors.ps1 index 8d859ae..88680c8 100644 --- a/scripts/governance-detectors.ps1 +++ b/scripts/governance-detectors.ps1 @@ -62,6 +62,25 @@ function Write-Section($title) { Write-Host ("===== $title =====") -ForegroundColor Cyan } +# INFORM-only flag sink for NEW detectors (C6 cite-2-tier, H24-4 pending-flip). +# Counted SEPARATELY in $script:InformCount and NEVER folded into $script:FlagCount +# (= the baseline TOTAL). Rationale (anti-Goodhart, owner-set): a brand-new net +# whose LOW hits are read by judgement on day one must not move the audited TOTAL +# down/up -- folding it would let "flag count fell" masquerade as progress and would +# hide whether the thing that changed was a false positive or a real witness. Fold + +# severity-raise is a POST-triage, owner-gated decision (see detector headers). Same +# [DETECTOR] line shape as Write-Flag so `comm before/after` cleanly isolates new lines. +$script:InformCount = 0 +function Write-InformFlag { + param( + [string]$Where, # file:line + [string]$Desc, + [string]$Resolve + ) + Write-Host ("[DETECTOR] {0,-4} | {1} | {2} | resolve: {3}" -f 'LOW', $Where, $Desc, $Resolve) -ForegroundColor Gray + $script:InformCount++ +} + # Make a path repo-relative for readable FLAG output (forward slashes). function Rel($full) { $r = $full @@ -1097,6 +1116,246 @@ else { } } +# --------------------------------------------------------------------------- +# C6 - cite-2-tier (INFORM-only, NEW; count SEPARATE, NOT folded into TOTAL) +# +# Two-tier citation check over a NARROW scope. A "cite" is a path:line token whose +# path ends in md|ps1|js|cs|ts|tsx. Tier-1: the file does not resolve -> cite-dead-file. +# Tier-2: it resolves but the cited line > EOF (ReadAllLines.Length) -> cite-line-past-eof. +# Both LOW (suite convention: an un-triaged net reads by judgement on day one; MED-noise +# + fold-into-TOTAL are a later, owner-gated call after triage). +# +# SCOPE (deliberately narrow, spec C2): docs/governance/*.md TOP-LEVEL only +# (adap-reports/ EXCLUDED -- ~90 lineage cites there are frozen history, not live +# claims) + .claude/commands/*.md + .claude/agents/*.md. +# +# THREE EXCLUSIONS, all measured on disk before shipping: +# (a) QUOTED cites -- inline-backtick via Test-Quoted (S123 citation-trap law: a +# prose matcher MUST use the enclosure use/mention discriminator) AND fenced +# ``` blocks via a fence-state toggle. MEASURED: 172/185 cites in scope sit +# inside backticks/fences (fable-real-runbook.md tables + code fence :103-109); +# scanning them bare would be ~172 false dead-file flags. +# (b) LINEAGE: the adap-reports/ dir (dir-exclude) + any line carrying the frozen +# marker U+1F9CA (built by code point, gotcha #30). fable-real-runbook.md:88 is +# exactly such a line (cite next to the retired-marker note). Declared: lineage +# OUTSIDE these two proxies accepts a first-run false positive; tune after triage. +# (c) SELF-DEF: this script is .ps1 + already in ExcludeExact; the run's spec + sub-MD +# live under .claude/workflows/runs/ which is already an ExcludeDirFragment -- so +# both are out of scope by construction AND re-checked via Test-Excluded per file. +# +# RESOLUTION (spec: repo-rel + familiar roots .claude/, docs/): try repo-rel exact, +# then .claude/ and docs/ prefix-joins, then -- for a BARE basename -- a +# recursive basename index built once over .claude/ + docs/. That index is why a bare +# hmw.js (lives at .claude/workflows/hmw.js) or reviewer.md (.claude/agents/reviewer.md) +# resolves instead of false-flagging (measured: 172/185 cites are bare basenames). +# +# HEADER LIMITS (declared, spec m-1): +# (a) soft-drift WITHIN eof is invisible (a stale :5 that should be :7 still resolves +# and is <= EOF -> not caught; the S108 +-1/2 class); +# (b) multi-root resolve can MASK a dead cite when a same-basename file exists at +# another root (index returns the first match; Ambiguous is noted in the flag); +# (c) a range cite file.md:12-15 is checked at its FIRST line (12) only. +# --------------------------------------------------------------------------- +Write-Section 'C6 - cite-2-tier (INFORM-only)' + +$FROZEN_MARK = U @(0xD83E, 0xDDCA) # U+1F9CA frozen/lineage marker (surrogate pair) +$FenceTriple = U @(0x60, 0x60, 0x60) # ``` (ASCII backticks; built to avoid quoting ambiguity) +$FenceRx = '^\s{0,3}' + $FenceTriple + +$c6Scope = @() +$govTop = Join-Path $RepoRoot 'docs\governance' +if (Test-Path $govTop) { $c6Scope += Get-ChildItem -Path $govTop -Filter *.md -File -ErrorAction SilentlyContinue } +$cmdDir = Join-Path $RepoRoot '.claude\commands' +if (Test-Path $cmdDir) { $c6Scope += Get-ChildItem -Path $cmdDir -Filter *.md -File -ErrorAction SilentlyContinue } +$agtDir = Join-Path $RepoRoot '.claude\agents' +if (Test-Path $agtDir) { $c6Scope += Get-ChildItem -Path $agtDir -Filter *.md -File -ErrorAction SilentlyContinue } +$c6Scope = @($c6Scope | Where-Object { -not (Test-Excluded $_.FullName) }) + +# Recursive basename index over the two familiar roots for BARE-basename resolution. +$citeBasenameIndex = @{} +foreach ($rt in @('.claude', 'docs')) { + $rtPath = Join-Path $RepoRoot $rt + if (-not (Test-Path $rtPath)) { continue } + Get-ChildItem -Path $rtPath -Recurse -File -ErrorAction SilentlyContinue | + Where-Object { $_.Extension -imatch '^\.(md|ps1|js|cs|ts|tsx)$' -and $_.FullName -notmatch '[\\/](bin|obj|node_modules)[\\/]' } | + ForEach-Object { + $bn = $_.Name + if (-not $citeBasenameIndex.ContainsKey($bn)) { $citeBasenameIndex[$bn] = New-Object System.Collections.Generic.List[string] } + $citeBasenameIndex[$bn].Add($_.FullName) | Out-Null + } +} + +function Resolve-Cite { + param([string]$Path) + $norm = $Path -replace '/', '\' + foreach ($c in @( + (Join-Path $RepoRoot $norm), + (Join-Path $RepoRoot (Join-Path '.claude' $norm)), + (Join-Path $RepoRoot (Join-Path 'docs' $norm)))) { + if (Test-Path -LiteralPath $c -PathType Leaf) { + return [pscustomobject]@{ Exists = $true; File = $c; Ambiguous = $false } + } + } + if ($norm -notmatch '[\\/]') { + $bn = [System.IO.Path]::GetFileName($norm) + if ($citeBasenameIndex.ContainsKey($bn)) { + $lst = $citeBasenameIndex[$bn] + return [pscustomobject]@{ Exists = $true; File = $lst[0]; Ambiguous = ($lst.Count -gt 1) } + } + } + return [pscustomobject]@{ Exists = $false; File = $null; Ambiguous = $false } +} + +# cite = .:. Leading '.' allowed (so .claude/... paths resolve). Range +# :12-15 captured at first line only (limit c). Lookbehind stops mid-word matches. +$c6CiteRx = '(? pending-flip-stale. +# +# SOURCE A = docs/HANDOFF.md, CURRENT SEGMENT ONLY. Boundary = the FIRST line that +# STARTS WITH "**Prev S" (regex ^, NOT substring). M-1 (measured): the current segment +# carries "... segment Prev S134 ..." in the MIDDLE of a line -- a substring match would +# cut the segment early and drop live lines; the ^-anchor does not. STATUS.md is OUT of +# scope v1 (M-2): its In-Progress section is now only S117/S113 lineage -> scanning it +# is background noise; widening is a post-triage call. +# +# MATCH (M-3): split each line on separators " " (space-middot-space) or " ; " +# -> logic fragments. A waiting token (CHO GAT | CHO ANH | cho-ky, built by code point) +# AND a mark code (RC-... signature OR [carry:slug]) must sit in the SAME fragment. A +# token inside `...`/fence is MENTIONED not used (Test-Quoted + fence). +# +# SOURCE B = .claude/governance/ACTIVE-MARKS.md. The mark's OWN table row (first cell) +# decides status: Active/Active-High -> stamped ; SUPERSEDED/DISABLE -> IM ; a RESOLVED +# note mentioning it -> resolved. stamped|resolved => FLAG ; superseded|not-found => IM. +# +# LIVE first-run EXPECTATION = 0 flags by design (measured: current segment has 0 +# waiting tokens). Value is in FUTURE sessions. Declared out-of-reach class: a proposal +# that landed in CODE but was never marked (S137) is a human-eye H24 view audit, not +# machine-visible here. +# --------------------------------------------------------------------------- +Write-Section 'H24-4 - pending-flip (INFORM-only)' + +$h244Flags = 0 +$handoffP = Join-Path $RepoRoot 'docs\HANDOFF.md' +$marksP = Join-Path $RepoRoot '.claude\governance\ACTIVE-MARKS.md' +if (-not (Test-Path $handoffP)) { + Write-Host ' [skip] no docs/HANDOFF.md - no pending surface' -ForegroundColor DarkGray +} +elseif (-not (Test-Path $marksP)) { + Write-Host ' [skip] no .claude/governance/ACTIVE-MARKS.md - cannot cross-check mark status' -ForegroundColor DarkGray +} +else { + $clsO = '[' + (U @(0x1EDC, 0x1EDD)) + ']' # O-horn-grave upper/lower + $clsA = '[' + (U @(0x1EAC, 0x1EAD)) + ']' # A-circumflex-dot upper/lower + $clsY = '[' + (U @(0x00FD, 0x00DD)) + ']' # y-acute lower/upper + $WaitRx = '[Cc][Hh]' + $clsO + '[ \-]([Gg]' + $clsA + '[Tt]|[Aa][Nn][Hh]|[Kk]' + $clsY + ')' + $MidSep = ' ' + (U @(0x00B7)) + ' ' + $SepRx = [regex]::Escape($MidSep) + '| ; ' + $CodeRx = '(?:RC-[A-Za-z0-9][A-Za-z0-9-]*)|(?:\[carry:[a-z0-9][a-z0-9._-]*\])' + $BacktickCh = U @(0x60) + + $script:marksLines = @(Get-Content -Path $marksP -Encoding UTF8 -ErrorAction SilentlyContinue) + + function Get-MarkStatus { + param([string]$Code) + $ownRowRx = '^\|\s*' + $BacktickCh + [regex]::Escape($Code) + $BacktickCh + $status = 'none' + foreach ($ml in $script:marksLines) { + if ($ml -match $ownRowRx) { + if ($ml -match '(?i)SUPERSEDED|DISABLE') { return 'superseded' } + if ($ml -match 'Active') { $status = 'stamped' } + } + elseif (($ml -match '(?i)RESOLVED') -and ($ml.Contains($Code))) { + if ($status -eq 'none') { $status = 'resolved' } + } + } + return $status + } + + $handLines = @(Get-Content -Path $handoffP -Encoding UTF8 -ErrorAction SilentlyContinue) + $boundary = $handLines.Count + for ($i = 0; $i -lt $handLines.Count; $i++) { + if ($handLines[$i] -match '^\*\*Prev S') { $boundary = $i; break } + } + Write-Host (" HANDOFF current-segment = lines 1..{0} (boundary '**Prev S' at line {1})" -f $boundary, ($boundary + 1)) + + $inFence = $false + for ($i = 0; $i -lt $boundary; $i++) { + $line = $handLines[$i] + if ($line -match $FenceRx) { $inFence = -not $inFence; continue } + if ($inFence) { continue } + foreach ($wm in [regex]::Matches($line, $WaitRx)) { + if (Test-Quoted $line $wm.Index) { continue } + # fragment enclosing the token = span between the nearest separators. + $left = 0; $right = $line.Length + foreach ($sm in [regex]::Matches($line, $SepRx)) { + if (($sm.Index + $sm.Length) -le $wm.Index) { $left = $sm.Index + $sm.Length } + elseif ($sm.Index -ge ($wm.Index + $wm.Length)) { $right = $sm.Index; break } + } + $frag = $line.Substring($left, $right - $left) + foreach ($cm in [regex]::Matches($frag, $CodeRx)) { + $st = Get-MarkStatus $cm.Value + if ($st -eq 'stamped' -or $st -eq 'resolved') { + Write-InformFlag ("docs/HANDOFF.md:{0}" -f ($i + 1)) ` + ("pending-flip-stale: current segment still waits on '{0}' but ACTIVE-MARKS has it {1}" -f $cm.Value, $st) ` + 'close/re-scope the HANDOFF waiting item, or re-open the mark if the wait is real' + $h244Flags++ + } + } + } + } + Write-Host (" H24-4 pending-flip flags = {0} [INFORM-only, LOW, NOT folded; 0 = designed first-run]" -f $h244Flags) -ForegroundColor DarkGray +} + # --------------------------------------------------------------------------- # Summary + C4 self-exclusion audit (RUNTIME proof) # --------------------------------------------------------------------------- @@ -1120,6 +1379,7 @@ if ($selfInScan -eq 0 -and $leaked -eq 0) { Write-Host '' Write-Host ("TOTAL FLAGS: {0}" -f $script:FlagCount) -ForegroundColor Cyan +Write-Host ("INFORM-ONLY (new nets C6 cite-2-tier + H24-4 pending-flip): {0} - counted SEPARATELY, NOT in TOTAL above (anti-Goodhart, owner-set; fold+sev-raise is post-triage)" -f $script:InformCount) -ForegroundColor DarkGray Write-Host 'NOTE: DETECT-only lowering net. Exit 0 always (never fails build). FLAGs are advisory.' -ForegroundColor DarkGray exit 0