[CLAUDE] Docs: S147 closeout — PE attach-fix (Trả lại) + project-dedup ship-prod

① nút đính kèm 'Bảng so sánh' gate drafter+phase (cả 2 app) · ② gom 3 cặp dự án trùng dấu-cách trên PROD (5 phiếu+5 NS repoint, 3 ẩn mềm) + vá gốc chuẩn hóa Code +4 test. CI #407 PASS, bundle rotate ×2 verify 2-nguồn. Session log + merge script (docs/changelog/data-fixes) + STATUS/HANDOFF + garble tally ×3 + harvest investigator/reviewer/cicd.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
pqhuy1987
2026-07-23 17:37:59 +07:00
parent 4510cea1e3
commit 5f6c3becfb
13 changed files with 264 additions and 179 deletions

View File

@ -1,14 +1,13 @@
# Reviewer Agent — Persistent Memory
- **S146 (07-22) PRE-COMMIT spec-v2-applied (governance-only, 20 file) — 2 MAJOR THẬT, cả hai của LEAD; nấc `verified` (tự chạy lệnh, không tin lead):** **F1** `session-end.md` ×2 còn `hook-3-path` **GẠCH NỐI** worker CE **đã chỉ đích-danh trong sub-file**, worker D vẫn rơi ⇒ class *"residual có người chỉ tận nơi vẫn rớt"*; bất-đối-xứng nội-bộ (`pause.md` đã 4-path, `session-end` chưa) = 2 command anh em nói ngược nhau về **cùng một hook**. **F2** phép quét cardinality của lead **siết LỆCH TRỤC** (co-occurrence CÙNG DÒNG + tập-file hẹp + 1 mẫu chữ) ⇒ chạy lại trên HEAD tiền-vá: bắt **7/11**, **lọt 4 ca thật gồm chính F1** (`3 path` dấu-cách KHÔNG khớp `hook-3-path` gạch-nối). **F3 HELD** — tự `git show da7ee8a` xác-minh hook 4-path nuốt `sessions/session-1/probe.md` + `settings.json` dùng `-File` ⇒ body re-đọc mỗi Stop, claim lead ĐỨNG. **F4** probe residue → ô-nhiễm ID-space `<N>` + làm ⑤ kêu tới khi push. 🔴 **Bài rút:** lead sửa 1 phép quét **4 lần/1 phiên** (rộng→hẹp→rộng→chốt) cố mã-hoá **ý-định NGỮ-NGHĨA** vào regex; nấc đúng = **lưới-soát-cho-người + allowlist CÓ TÊN + use⟂mention**. Lần 4 = **citation-trap**: bộ dò bắt chính nốt-vá vì nốt vá trích-dẫn giá-trị cũ.
- **[verbatim → git 8b6df0a closeout] S146 (07-22) PRE-COMMIT spec-v2-applied (governance 20 file) — 2 MAJOR THẬT (cả hai của LEAD); nấc `verified` tự-chạy-lệnh không-tin-lead:** F1 `session-end.md` còn `hook-3-path` GẠCH-NỐI worker CE đã chỉ đích-danh (class "residual có người chỉ tận nơi vẫn rớt") + bất-đối-xứng nội-bộ (`pause.md` đã 4-path). F2 phép quét cardinality của lead siết LỆCH-TRỤC (co-occurrence CÙNG-DÒNG + 1 mẫu-chữ) → re-run HEAD tiền-vá lọt 4 ca thật gồm chính F1. F3 HELD (git show da7ee8a: hook 4-path + `-File` re-đọc mỗi Stop). 🔴 Bài rút: lead sửa 1 phép quét 4 lần/phiên vì mã-hoá ý-định NGỮ-NGHĨA vào regex; nấc đúng = lưới-soát-cho-người + allowlist CÓ TÊN + use⟂mention; lần-4 = citation-trap (dò bắt chính nốt-vá vì nó trích giá-trị cũ).
- **[→ archive/2026-07.md @S145-curate] S145 Axis-E lane (tiep/pause/snapshot + CROSS-CUT) SPEC apply-hub — FAIL 2C/1M/4m:** corroborated Axis-A "4 surface→2"=FALSE independently. UNIQUE 2 seam-catch: (C↔E CRITICAL) C.2 hook 3→4 path (+sessions/) phá Sàn-3 tiep.md — "3 path" hardcode 4 site (:21/:23/:75/:78) ⇒ sessions/ orphan KHÔNG signal = blind-spot ON RECOVERY FLOOR + misclassify-dirt logic-bug; cả 2 death-path ko nhắc ripple. (MAJOR) session_ctx_kb=64 nghịch owner-authority (OWNER-GATED + K6.2 cấm mượn-số-hub-chưa-đo) + ghost-wire #H18 (0 script đọc key). LESSON: bất-biến chia-đôi giữa 2 axis nằm ĐÚNG SEAM → chỉ cross-cut sweep bắt; "áp hub-answer" ≠ "số owner-giữ".
- **[→ archive/2026-07.md @S145-curate] S145 lane-4 (Axis-D 5-vòng-closure) SPEC apply-hub — PWF 2M/1m:** D2 RULING (owner-asked): session-start-KIỂM defer LEGIT — canonical "hai đầu" binds MEASURE (H1 báo-diff session-start.md:127 both-ends), self-verify col=CLOSE-time ⇒ 3 KIỂM end-only canonical-consistent. 🔴 phép-4 LANDMINE live: `agent-memory/tooling-harvest-audit/` EMPTY + h24/sleep-audit folders MISSING; tooling-harvest-audit AUTO-fires close ⇒ ko-write-sổ = phép-4 FAIL. FIX: D1 acceptance per-check disk-evidence ko bare-PASS + D2 NAME defer-doc-site. LESSON: 'vai-có-sổ' acceptance ⇒ MUST `ls agent-memory/<role>/` (folder≠sổ).
- **[→ archive/2026-07.md @S145-curate] S145 C7-lane (Axis A) — PWF 1C:** spec "4 surface→2" stale-fix = FALSE (`nhip-no-probe.ps1` 4 caller THẬT, header self-doc đúng; spec conflate 2 `*-probe.ps1`); A2 grep-"4 surface"=0-hit = ANTI-TEETH Goodhart (PASS bằng xóa info đúng). LESSON: stale-fix claim verify caller-trên-đĩa trước; 2-script-same-suffix = conflation-vector.
- **[→ archive/2026-07.md @S145-curate] S145 Axis-E lane — FAIL 2C/1M/4m:** cross-cut seam catch (hook 3→4 path sessions/ orphan phá Sàn-3 tiep.md; session_ctx_kb=64 nghịch owner + ghost-wire #H18). LESSON: bất-biến chia-đôi giữa 2 axis nằm ĐÚNG SEAM → chỉ cross-cut sweep bắt.
- **[→ archive/2026-07.md @S145-curate] S145 lane-4 (Axis-D) — PWF 2M/1m:** phép-4 LANDMINE (`agent-memory/tooling-harvest-audit/` EMPTY, auto-fires close ⇒ phép-4 FAIL). LESSON: 'vai-có-sổ' acceptance ⇒ MUST `ls agent-memory/<role>/` (folder≠sổ).
- **[→ archive/2026-07.md @S145-curate] S145 C7-lane (Axis A) — PWF 1C:** spec "4 surface→2" stale-fix FALSE (4 caller THẬT); grep-"4 surface"=0-hit = ANTI-TEETH Goodhart. LESSON: stale-fix verify caller-trên-đĩa; 2-script-same-suffix = conflation-vector.
- **[→ archive/2026-07.md @S145-curate] S145b (07-22) GATE roster #2/#3 h24-audit+sleep-audit (18→20) — PASS 1m:** implementer vá ĐÚNG mọi S145a-finding + tự sweep 2 NUMERIC site ngoài checklist. 1 MINOR measured-label: `README:249` "17 folder" falsified by ls=18 (tooling-harvest-audit RỖNG). LESSON: đếm VALID_ROLES = per-file grep bidirectional KHÔNG regex (hmw.js `[2]`/`[S110` comment lừa parser).
- **[→ archive/2026-07.md @S145b-curate] S145a — GATE roster vai#1 FAIL 3M/4m:** NUMERIC "roster 17" hardcode trốn name-enum sweep ⇒ LUẬT sweep repo-wide grep CẢ numeric LẪN name-enum; "self-verify 0-stale" FALSIFIED (scoped≠repo-wide). Superseded S145b PASS.
- **[→ archive/2026-07.md @S145b-curate + sub-reviewer-0.md] S143 — GATE outward FAIL 1C/4M:** CLASS `bằng-chứng-tự-huỷ-sau-squash` (cite outward = commit SỐNG-sau-squash, KHÔNG `wal:`); `git status --porcelain` = bước ĐẦU outward-gate; số tuyệt-đối neo-mốc (46 vs 47 vs 45); errata CẤM sửa file đã-stamp; #53 "ghi-đĩa-trong-lúc-làm" vớt.
- **[→ archive/2026-07.md @S140/@S134] S139 · S134b · S133 (digest, 1 mệnh-đề/entry):** S139 GO — re-measure MỌI acceptance từ git HEAD (không tin sub/EM) + **m-3 no-self-exempt: chấm cả edit vào file CHÍNH VAI MÌNH**; nhãn "measured" sống CHỈ KHI falsify-path tồn-tại ∧ reviewer CHẠY ∧ nó đứng · S134b PASS — "insertion-only + `grep '^-'`=0" chắc hơn diff-mắt; D4-persist = trace TỪNG caller tới SaveChanges · S133 PWF — literal-grep 4-site PASS nhưng `.Phase = <biến>` lòi 2 đường GIÁN TIẾP bypass helper ⇒ **"mọi nhánh set X" phải grep CẢ assignment-qua-BIẾN** (#81).
- **[→ archive/2026-07.md @S145b-curate] S145a·S143 (digest, archived):** S145a NUMERIC "roster 17" hardcode trốn name-enum sweep ⇒ sweep repo-wide CẢ numeric LẪN name-enum (superseded S145b PASS) · S143 CLASS `bằng-chứng-tự-huỷ-sau-squash` (cite outward = commit SỐNG-sau-squash) + số neo-mốc + errata CẤM sửa file đã-stamp + #53 ghi-đĩa-trong-lúc-làm.
- **[→ archive/2026-07.md @S140/@S134] S139·S134b·S133 (digest, archived):** S139 re-measure MỌI acceptance từ git HEAD + no-self-exempt (chấm cả file CHÍNH VAI MÌNH); "measured" sống CHỈ KHI falsify-path CHẠY ∧ đứng · S134b insertion-only + `grep '^-'`=0 chắc hơn diff-mắt · S133 "mọi nhánh set X" phải grep CẢ assignment-qua-BIẾN (#81).
> **Persistent diary cross-session.** Auto-injected first ~200 lines at spawn (L1 HOT).
> Update BEFORE every stop. Tiered Memory v1: L1 HOT cap ~17KB (hook 24.4KB read-limit) · L2 `archive/` on-demand · L3 RAG `search_memory` just-in-time. Keep entry ≤ 1.5K chars (gotcha #53).
@ -25,6 +24,7 @@
- [S113 Supplier import v2 close-review (owner anh Kiệt)](project_s113_supplier_import_v2_review.md) — GO-WITH-ADJ 2 must-fix (consumers không pass published=true → drafts leak). Lesson: "filter added" ≠ "drafts hidden" — grep-all-consumer + create write-path.
- [S118 Procurement master-access seeder review](project_s118_procurement_master_access_review.md) — PASS(cond); MAJOR Reports.Read leaks financials + Suppliers.Update grant ≠ edit. Lesson: menu-flag grant ≠ API capability; bare `[Authorize]` GET = open-to-all.
- [S123 governance 4-change review (backtick-guard + H24-3 + retire dạng-3 + mark)](project_s123_governance_4change_review.md) — PASS_WITH_FIXES; CAUGHT H24-3 thiếu enclosure-guard mà cùng diff vừa chứng cần (gen-2 citation-trap) + greedy `.*` lấy `(S<N>` CUỐI≠MAX + lý-do-retire áp cho dạng-2 thì giết C8. Q5 "HOÀN-THÀNH mark" = nguỵ-biện. Q8 ENDORSE không-bump.
- [S147 Project whitespace-dupe merge verify](project_project_dupe_merge_verify.md) — 7/7 PASS(2 FK-terminology corrections); "FK Projects" COMMENT ≠ physical FK (sys.foreign_keys=0 to Projects, all loose-Guid); seed-durability FORCES survivor=no-space blanket; INNER-join+filter=silent-vanish→repoint-before-soft-delete; prod ref-dist unverifiable (Server=localhost+secret).
---
@ -80,23 +80,16 @@ Adversarial pre-commit reviewer SOLUTION_ERP. Read-only verify + live curl prod
## 📅 Recent activity (compressed — full verbatim → `archive/2026-06.md` + `archive/2026-07.md` via `archive/_INDEX.md`)
- **S147 (07-23) DIAGNOSIS-review PE attach TraLai (no diff — verify root-cause + stress fix) — Diagnosis PASS 5/5, fix CORE-safe/EXT-unsafe:** 5 claims verified from disk; BE-no-guard CONFIRMED **intentional** by S78 changelog L9 ("handler KHÔNG guard drafter-only → approver upload no-403") + sole pipeline behavior=ValidationBehavior. 🔴 **MAJOR blind-spot:** `attachEditable=isDrafter&&isEditablePhase` SAFE for GeneralAttachmentsSection (:2013 readOnly=raw, no carve-out) but UNSAFE for SupplierAttachmentsCell (:2758) whose readOnly=**itemsReadOnly** (`readOnly&&!approverEditMode`, Mig28-F3 ChoDuyet approver-edit) → naive REPLACE breaks approver QuoteDocument edit in ChoDuyet; SAME gap in optional BE guard (carve-out {ChoDuyet+ApprovalAttachment} misses ChoDuyet+QuoteDocument). **Scope trap:** isDrafter@:140 in MAIN scope, OUT-of-scope at :2013/:2758 (child comps take only {ev,readOnly}); changing :421 over-broadly hits HoSoLinkRow:2017. **Completeness:** WORKSPACE (readOnly=false, picker editableOnly∋TraLai) already edits comparison-doc in TraLai → bug is LIST-detail-only (:574/:669 hardcode). LESSON: **decouple a gate → trace if shared prop already carries a carve-out (itemsReadOnly ≠ raw readOnly); "same fix" for sibling surface may hit a DIFFERENT gate source.**
- **[→ archive/2026-07.md @S134] S131b GATE#2 outward follow-up — PWF 1M:** follow-up bounded-source phải GIỮ con-số source ("hàng loạt" re-inflate "3 closeout" = re-introduce class morning-gate đã gỡ) · verbatim-quote owner so TỪNG CHỮ kể cả homophone x/s.
- **[→ archive/2026-07.md @S134] S131 GATE outward 3-op-gap — PWF:** → [topic](project_s131_h24_h22_3gap_outward_gate.md). Số atomic đúng HẾT vẫn fencepost (ghép lệch cột-mốc đẻ "gấp-đôi" 2× khi thật 1.6×) — hero-ratio re-derive từ raw + đếm tay từng nhãn.
- **[→ archive/2026-07.md @S134] S129 adap-errata-EOL 2-lane — GO-WITH-FIXES ×2:** writer-only = NỬA-VÁ (consumer-sweep áp cho cả ĐỀ-XUẤT-VÁ) · tally "7/7 ADOPTED" = rung-flatten · quick-test tự chạy lại = chứng không-bịa rẻ nhất · story-delta BỊA bắt bằng glob-scope.
- **[→ archive/2026-07.md @S128/@S126] S124 ×2 + S125 ×2 (digest):** push-guard "ahead-of-broadcast" OVERCLAIM (looser ≠ ahead) · do-token trap bắt WHILE adopting ⇒ verify = re-Read full + tự đọc truncation-line · notice-N = CẬN-TRÊN heuristic · false-TAMPER → RCA verifier-bệnh (sibling-test 2-CHIỀU: MATCH⇒file-bệnh · FAIL⇒verifier-bệnh); stamp-then-edit = re-stamp + re-selftest cùng lượt.
- **[→ archive/2026-07.md @S134] S123 governance 4-change — PWF:** → [topic](project_s123_governance_4change_review.md). 🔴 #53 garble tại TAO ⇒ ghi diary TRƯỚC return · vá-1-lớp ⇒ grep MỌI matcher cùng-lớp TRONG diff.
- **[→ archive/2026-07.md @S126/@S134] S123·S124·S125·S129·S131·S131b digest (all archived):** S131b follow-up phải GIỮ con-số source · S131 số-atomic-đúng vẫn fencepost → hero-ratio re-derive từ raw ([topic](project_s131_h24_h22_3gap_outward_gate.md)) · S129 writer-only = NỬA-VÁ + quick-test tự-chạy = chứng rẻ nhất · S124/125 do-token trap → re-Read full + sibling-test 2-CHIỀU (MATCH⇒file-bệnh·FAIL⇒verifier-bệnh) · S123 🔴 #53 ghi diary TRƯỚC return + vá-1-lớp grep MỌI matcher cùng-lớp ([topic](project_s123_governance_4change_review.md)).
- **Digest S93→S117 (verbatim → `archive/2026-07.md`; 1 mệnh-đề/entry):** S93 code-gate re-derived denom · S97 default-flip byte-mirror SHA ×2 · S98 Windows byte-verify = .NET (MSYS strip
báo sai) · S100 HELD stale run-id NOT-stamped · S101 persist-claim cần reader-side · S108 outward-claim "đã sửa X" phải cat X trước gate · S109 gist meta-count ≠ disk · S110 claim-về-code grep lại kể cả reword · S111 nâng-nấc-quên-sync cùng-diff · S115 verify EACH regex-alt by-hand · S116 persist-claim = tracked + 0-drift · S117 2-tier guard compare SUM-EXPRESSION.
- **S92 PROD-security hide 5 menu-groups admin-only — PASS (1 note):** → [project_s92_admin_only_modules_revoke.md](project_s92_admin_only_modules_revoke.md).
- **June-2026 digest — LESSON-ONLY (verbatim → `archive/2026-06.md` + `_INDEX`):** merge-distill fabricates false-specificity ⇒ QUALITY gate AFTER presence · sha = self-declared NOT recompute · fail-closed guard BEFORE terminal-state + server-recompute · TRACKED = check-ignore ≠ ls-files · menu-hide ≠ API-lock · single→multi stops at display-layer.
- **[→ archive/2026-07.md @S128 + topic] S112 close-reviews+FINAL — GO 0-must:** derive guard từ ENDPOINT authz; EDGE-5 gác FROM-state ĐỈNH method; self-flip ≠ external-accept. → [topic](project_s112_supplier_import_review.md).
- **[→ archive/2026-07.md @S128] S126 A1-H23-probe + email-H23-gate — gate FAIL bắt 3 lỗi trước stamp:** số AGGREGATE cumulative KHÔNG vào outward artifact (evidence bền = per-lane run-id) · "ba việc" = 2 ASK (mở thư đếm thật) · self-obs R1-open → hedge + quy-thuộc. Stamp `945cf3ad`. Evidence: runs/2026-07-16-S126-adap-spec-execute/.
- **[→ archive/2026-07.md @S134] S128 D-review 2-lane adap — GO-COMMIT 2/2:** direction-of-error quyết mức lỗi outward (lệch CONSERVATIVE = minor) · sha-variant-per-publisher: brute-force canonical-variant với known-good TRƯỚC khi phán tamper · soi literal-fidelity evidence-paste CẢ KHI giá-trị đúng. Trace: `runs/2026-07-16-S127-adap-dot-16-07/`.
- **[→ archive/2026-07.md @S134] S128 fable-real #2 spec-execute — GO-WITH-FIXES 4SF:** lệnh verify trong spec = CODE chạy thử trước (2/4 sai thật) · Get-FileHash ≠ body-sha (sai-loại-hash) · fold = disposition TỪNG DÒNG.
- **[→ archive/2026-07.md @S134] S127 fable-real #1 gate đầu-vào — GO-ADAP, BÁC claim hub:** hedge broadcast test bằng MỞ config THẬT (rag.json override ACTIVE) · "already-aligned" tinh-thần ≠ luật. Full: `runs/2026-07-16-S127-adap-dot-16-07/sub-reviewer-1-verdict.md`.
- **[→ archive/2026-07.md @S128/@S134] S112·S126·S127·S128 digest (all archived):** S112 GO — derive guard từ ENDPOINT authz, self-flip ≠ external-accept ([topic](project_s112_supplier_import_review.md)) · S126 gate — AGGREGATE cumulative KHÔNG vào outward artifact, "ba việc"=2 ASK · S128 — direction-of-error quyết mức lỗi outward + brute-force sha-variant TRƯỚC phán tamper + Get-FileHash ≠ body-sha · S127 — hedge broadcast bằng MỞ config THẬT.
---

View File

@ -0,0 +1,25 @@
---
name: project-project-dupe-merge-verify
description: S147 adversarial verify of Project whitespace-dupe merge plan (FLOCK 01/FLOCK01) — FK-in-comment ≠ physical FK; seed-durability forces survivor; INNER-join+filter = silent vanish
metadata:
type: project
---
# Project whitespace-dupe merge — adversarial verify (2026-07-23)
Investigator plan: merge "FLOCK 01"/"FLOCK01" (+prod FLOCK 03, CAL 01) space-dupes → no-space canonical, retire space-variant, fix dupe-check root cause. Verified all 7 claims + stress i-v. Overall plan SOUND/safe-by-design; 2 terminology corrections; biggest residual = prod ref-distribution unverifiable from dev.
## Reusable lessons (load-bearing)
- **"FK Projects" in a code COMMENT ≠ physical FK.** `PurchaseEvaluation.cs:15` comment says "FK Projects" but `sys.foreign_keys` scan = ZERO FKs to Projects (68 total FKs in db, none ref Projects). All 3 refs (Contracts/PurchaseEvaluations/PeWorkItemBudgets) are **loose-Guid** (HasIndex only, no HasOne). Claims 1+2 inherited the wrong "FK" word. **Always verify FK reality via `sys.foreign_keys`, not the entity comment.**
- Loose-Guid (no FK) makes merge repoint SAFER re: ordering (no constraint breaks) but removes ALL DB safety net: orphan ProjectIds already possible, no cascade/restrict, a botched/incomplete repoint is NOT caught by the db.
- **Blast radius via `sys.columns LIKE '%ProjectId%'` = exactly 3 tables** (authoritative). No denormalized ProjectCode/MaDuAn column anywhere (PE resolves Code via JOIN `db.Projects on e.ProjectId equals p.Id`, DTO projects `x.p.Code`). Only PeWorkItemBudgets has unique index touching ProjectId (filtered `(ProjectId,WorkItemId) WHERE IsDeleted=0`) → sole merge-collision surface.
- **INNER join + HasQueryFilter(!IsDeleted) = silent vanish.** PE list (`PurchaseEvaluationFeatures.cs:579`) + Contract list (`ContractFeatures.cs:294`) INNER JOIN Projects. Soft-deleting a Project drops every still-referencing row from lists (no error). FORCES repoint-BEFORE-soft-delete + verify 0 live refs (count=0/0/0) before retiring. Detail path (`ContractFeatures.cs:435` FirstOrDefault + `?.Name ?? ""`) tolerates missing → list/detail asymmetry.
- **Seed-durability FORCES survivor choice (not ref-location).** Ungated `SeedRealMasterDataAsync` (`DbInitializer.cs:128`, outside `if(!demoSeedDisabled)`) emits no-space FLOCK01/FLOCK03/CAL01 every startup; idempotency = exact Code via `db.Projects.Select(Code)` which IS subject to query-filter (no IgnoreQueryFilters). ⇒ soft-deleted no-space canonical is invisible to Select → RE-CREATED (resurrection). Space-variant in NO seed → retire = stays dead. So survivor MUST be no-space **blanket**, even if prod space-variant holds the refs (refs just get repointed; loose-Guid unconstrained). App delete = soft (`AuditingInterceptor.cs:56-61` Deleted→Modified+IsDeleted=true).
- **MaHopDong irreversibility:** embeds project.Code at gen (`ContractCodeGenerator.cs:32-33`), immutable (`ContractWorkflowService.cs:166` if-null guard; no Update rewrites). Repoint ProjectId does NOT fix embedded space in contract number — accepted limitation.
- **Root cause:** manual Project Create/Update store Code raw (no trim) + dupe-check EXACT equality (`ProjectFeatures.cs:95,138` `x.Code==request.Code`). No Project import exists. Trim-only INSUFFICIENT (embedded space survives) — needs whitespace-collapse on BOTH paths, ideally + normalized-key unique index (app-check races under concurrency).
## Prod-access constraint (stress v)
`appsettings.Production.json`: `Server=localhost;...User Id=vrapp;Password=__SET_VIA_SECRETS__`. Prod SQL bound to localhost on VPS (not network-exposed) + secret creds + S134 SSH-crash gotcha ⇒ NO read-only path from dev. Prod ref-distribution (which row holds refs per pair) UNVERIFIABLE pre-execution — the plan's single biggest residual unknown.
## Dev DB snapshot (2026-07-23)
70 live projects, 0 soft-deleted. ONE whitespace anomaly `[FLOCK 01]` (D680DB3D, 0C/0PE/0budget). `[FLOCK01]` (F1B311EE) = 2C/2PE/0budget. ONE collision group (flock01). CAL01/FLOCK03 exist no-space only; FLOCK 03/CAL 01 space = prod-only.