# Reviewer Agent — Archive 2026-07 (L2 verbatim, FROZEN additive-only) > **Recovered S102 (2026-07-06):** 5 entry verbatim (S97 · S97-bis · S98×3) bị **cut-not-moved** tại commit `f229b07` (S101 nén L1, digest claim "Detail → `archive/2026-06.md`" nhưng verbatim chưa từng được move — H2 harvest-curator Fidelity-FLAG S102). Trích **content-exact** từ `git show 5ee32c0:.claude/agent-memory/reviewer/MEMORY.md` (PS .NET per-line match, line-ending normalize LF, 0 ký tự mất). Thứ tự giữ nguyên như L1 gốc (newest-first: S98×3 → S97-bis → S97). > Quy tắc file: NEVER rewrite existing bytes; entry mới APPEND cuối file. Map: `archive/_INDEX.md`. - **S98 (2026-07-02) FIDELITY GATE gist impl-frontend 2026-H1 (10 record → 6 cụm + 5 reflection) — PASS-với-sửa (1 minor):** 34/34 substring-pointer count==1 (grep -o -F đếm occurrence, gồm cặp bẫy "gotcha #50"≠"gotcha#50" resolve 2 record khác nhau đều hợp-cảnh). 3 interpretive-flag verify GROUND-TRUTH ngoài verbatim: double-rAF (code ListPage:270 comment "2 rAF để browser commit translate-x-full TRƯỚC" + duration-200) · 2 PageHeader song-song (4 file disk thật ×2 app) · wildcard `ev.*Note` theo-từng-mut (đúng 3 call-site 1770/1785/1841). FLAG cwd-misland hướng-chéo: session-log S76:40 CORROBORATE verbatim (cd fe-admin → rơi fe-user/.claude) + .gitignore L109-111 comment trung-tính → draft trung-tính ĐÚNG, không sửa hướng. Sửa duy nhất: R4 parenthetical nói chuỗi "nằm trong chính gist" — misleading, chuỗi resolve count==1 trong archive. Lesson: fidelity-gate 3 lớp = so-verbatim + pointer-arithmetic + ground-truth-code cho MỌI chỗ gist DIỄN GIẢI vượt verbatim; honest-empty BẤT-NGỜ="không" > bịa filler; verbatim TỰ mâu-thuẫn (S52-vs-S53) → gist flag discrepancy chứ KHÔNG resolve bịa (anti-S88-fabrication-by-merge, lần này draft làm đúng). - **S98 (2026-07-02) VERIFY LANE V3 cicd-monitor L1-curate moved-not-cut — PASS (0 blocking, 3 minor):** sha256 line-level backup-L73/74 == archive-L7/8 (2398/1909B text) + byte-arithmetic đóng EXACT (removed 4309 raw − stubs 1451 = 2858 = size-delta 19917→17059) + diff duy-nhất `73,74c73,74` + CR/LF profile 86/86→86/86 không đổi + FROZEN archives 0-diff + _INDEX 78=2+39+20+6+7+3+1 pointer-resolve count==1. **Tool-lesson Windows byte-verify:** MSYS grep/sed/awk = TEXT-MODE strip `\r` (grep -c `\r` báo 0 trên file CRLF thuần!); od-token-pipeline đếm sai (641 vs 86 — token-split artifact); ground-truth = `.NET ReadAllBytes` / `wc -c` / `tr` pipe / `od -c` tail. Moved entries CRLF→LF normalize (encoding-only, 0 ký tự mất — Write tool ghi file mới LF uniform). Minor caught: MEMORY.md "Last curate" ledger vẫn S80 (S98 chưa ghi sổ, discoverable qua stub "(curate S98)"); archive-header chữ "byte-exact" đúng trừ CR-terminator. - **S98 (2026-07-02) VERIFY LANE V1 re-tier mega-line STATUS/HANDOFF conservation (uncommitted) — PASS (0 mismatch):** blurb S94+S93 cắt khỏi mega-line = VERBATIM trong archive tier-S98 (STATUS IndexOf ordinal 9412/11090 · HANDOFF 6147/7775; HEAD cross-check cùng blurb, HANDOFF lệch +51 = đúng bundle-hash morning-edit TRƯỚC blurb). **Proof-of-no-other-deletion = arithmetic full-accounting** prefix+b94+sep(` · `,3)+b93+tail(125=old-pointer) == lineLen exact ×2 file — mạnh hơn spot-check. Old-pointer tái hiện trong pointer mới (archive-S98 + archive-S94 đều =1). Kỹ thuật-bẫy: commonPrefix lấn 1-char (`*` đầu `**Prev` trùng `*` mở italic pointer mới) → Replace-decompose trên removed-region FAIL giả; fix = IndexOf(blurb) trên FULL line. Line-count bằng (92/92, 12/12) → index-by-index diff enumerate đủ 6+2 dòng vào allowed-list. Flagged: archive `??` UNTRACKED — phải `git add` cùng commit kẻo pointer gãy. Read-tool truncate dòng >2K = KHÔNG verify được mega-line → PS ReadAllLines UTF8 + ordinal IndexOf là đường duy nhất. - **S97-bis (2026-07-01) PE EndsBeforeCeo CONFIG→RUNTIME + Mig 60 backfill (bug anh Kiệt FDC, cross-stack+mig, live UAT) — PASS (0 issue):** field `EndedByLevelFinalize` set true DUY NHẤT nhánh level-finalize service:871 (grep-all confirm 5 nhánh DaDuyet: 671 drafter-auto / 873 finalize-SET / 911 ccm-delegation / 943 all-steps-CEO / 1049 V1-legacy — chỉ 873 set, 4 nhánh còn lại giữ false = đúng semantics). 4 projection nhất quán: detail ternary `phase==DaDuyet?field:true` (:1153) · List/Inbox `Phase==DaDuyet?field:config-subquery` (:647/:767) · ListApproved direct field (filter DaDuyet :176). **Migration 3-file OK** (Designer+Snapshot có bit-NOT-NULL-default-false); backfill marker `LIKE N'%Duyệt KẾT THÚC tại%'` KHỚP-EXACT service comment:883 (system prefix, user-comment nối SAU) + table `PurchaseEvaluationApprovals` verified (config:148+DbSet) + `Phase=7`=DaDuyet verified enum. ccm-delegation comment `[CCM duyệt done miễn CEO]` KHÔNG match backfill → false nhất-quán runtime. **EF-translate ternary List/Inbox CONFIRMED runtime** (không giả định): `PeDraftVisibilityTests` gọi ListPurchaseEvaluationsQuery full-projection nằm trong 395 Infra PASS. FE 2-app SHA256-IDENTICAL `b7abbc2f`, gate `finalizeFlowStep=endsBeforeCeo?find:null` + banner:278 + type `endsBeforeCeo:boolean` có sẵn 2 DTO. **Build slnx 0w/0e + 440 test (45D+395I) 0-fail + tsc×2 exit-0** (self-verified, không tin claim). Test repro `peFinButWentCeo` (cùng-config finalize + field=false → EndsBeforeCeo=FALSE) = contrast quyết-định runtime-vs-config, xuất sắc. **Anti-pattern-none:** 11-file đúng-scope 0-drift, extend-in-place test NET+0-method giữ 440. Lesson: backfill LIKE-2-wildcard trên chuỗi VN-đặc-thù = false-positive risk MINOR-lý-thuyết (chỉ phiếu DaDuyet-hiện-tại 1-lần, UAT ít-phiếu) KHÔNG đủ FAIL. Config→runtime split đúng: chỉ THÊM chính-xác cho DaDuyet, non-DaDuyet giữ heads-up config như trước = không regression. **Re-affirmed @S97 Part-5 session-review lane** (spawn fail-return-schema → verdict recovered từ chính entry này per #53-recover-from-diary; em-main grep bổ-sung: 0 wrong-table pattern nào khác ngoài Mig 60 — đã fix Mig 61). *(addendum on-behalf H2-proposed @S98)* - **S97 (2026-07-01) PE finalize UAT ×2 app: reword badge + đảo default checkbox opt-out→opt-in (uncommitted, prod-live anh Kiệt FDC) — PASS (0 issue):** 4 hunk/file × 2 = 8 total, 12ins/12del, no thừa. E1 `useState(true→false)` L57 · E2 reset `setApplyLevelFinalize(false)` L221 · E3 helper-text reword (strings KHỚP spec verbatim) · E4 badge `không trình tới`→`Kết thúc tại {finalizeLevelName ?? finalizeStepName ?? 'cấp trên'}` + template-literal title. **SHA256 full-file IDENTICAL** `bcf812fd…` ×2 + git-diff --no-index exit-0. **Comment L121 `không trình tới` INTACT** (bare-string 2-site: comment giữ + JSX đổi) + **`e.target.checked` handler L664 INTACT** (spec correctly NOT flip). Logic-non-break VERIFIED: default-false → eligible-untick → `sendPrice`(L171)=false + `shouldPickPrice`(L496)=false → price-picker KHÔNG bắt (spec pt6 ✓); payload L200 `(approverFinalizeEligible ? applyLevelFinalize : true)` = pre-existing S96 opt-out no-op cho non-eligible, unaffected by flip. Type `finalizeStepName/LevelName: string|null` (purchaseEvaluation.ts:149-150) → `??`-chain TS-safe. 0 BE/test/mig leak. Build fresh ~17:55 ×2 (fe-user hash `DxUomy4C` KHỚP impl-claim; fe-admin rotate `DkyQ0xCd`→disk `l_kwCZIF` = #69 normal). Anti-pattern-none: precedent-backed cosmetic+default-flip, byte-mirror tight. - **S101 H18 WF2 governance re-run (self=workflow-lane · em-main synthesized):** re-verified S100 Harness-18 adopt (`5ee32c0`, governance-only) — original WF2 `wf_31ea3985-92c` lost to CLI-restart → fresh `wf_955643c3-f7d` **PASS_WITH_CONCERNS**. Lane-A detector-teeth PASS (fault-inject 4/4 `-RepoRoot` temp-tree — proved detector FLAGS injected-stale, not happy-path). Lane-B caught **1 CONCERN em-main missed in S100 sweep**: `workflows/README.md:51` stale label "ledger orphan-scan" (NO `_ledger` token → grep-exact sweep skipped) → FIXED S101. Lesson: **exact-token sweep misses paraphrased labels** — widen to concept-phrase when retiring a named artifact. Lane-C **#53 return-garble** (workflow-lane returned no StructuredOutput) → recovered first-hand, NOT re-spawned (`feedback_agent_return_garble_recover`). - **S101 H19 WF2 review LANE-C (adap-reports + honesty · self=reviewer · `wf_5f308fd8-744`=WF1):** PASS. 4 adap-reports (H19 fable-clone + 3 model-tier) + send-email 6c. Hashes recompute indep MATCH (H19 `6909299a` + model-tier `ee00d253/a7ff304b/eed277f7`), all carry `reviewer_gate: PASS`. 12/12 honest; Q2 hysteresis `0.85/5/2` verbatim budget.json:35-37. Danger-phrase "verified" only in G-011 legend + "verified-pending-restart"; nấc="designed+will-dogfood, thật-mode CHƯA chạy". **Lesson: hex→SHA disambiguation — recompute BOTH strip/no-strip variants to prove a hex string is a content_sha256 BODY-hash not a commit-SHA (line-29 `5f511fe5→5f8b8504` = hash-transition, `git cat-file`=not-commits, claim TRUE presentation-nit only).** - **S101 H19 fable-clone WF2 Lane-A (toggle mechanism) — PASS_WITH_CONCERNS (1 CONCERN, 0 BLOCKING):** 3 Lane-A asks all CONFIRMED — (Q1) `/fable-real`=Write · `/fable-clone`=Remove-Item mirror ultra-on/off, both carry no-hot-reload warning; (Q2) semantic INVERSE (marker-absent=ảo-DEFAULT · present=thật) consistent across 8 statements + `git check-ignore .claude/fable-real-mode.on`=IGNORED (line 92 AFTER `!.claude/**` neg line 83, verified `check-ignore -v`) + tracked cmd-file NOT-ignored; (Q3) GAP-1 scope-guard "N lane CÙNG 1 vai, KHÔNG mixed-roster" pinned in BOTH cmd-files + §K.C, and hmw.js VALID_ROLES independently confirmed = all 9 roles no 2-position gate (resolveModel unrestricted) → GAP-1 leak framing ACCURATE not fabricated. **CONCERN (refutation that landed):** marker is a WRITE-ONLY dead artifact — `/fable-real.md:10` claims "Mode persist qua marker → SỐNG qua session/compact" but NOTHING reads `fable-real-mode.on`; `/session-start` BƯỚC 0.5 reads only `hmw-mode.on` and was NOT extended (session-start.md unmodified in git status, empty grep for any reader). Write half-loop exists, read→report→route half-loop absent → wording overstates mechanism. Non-blocking because vacuously-met-today (all-inherit → 2 positions ALREADY top-model → 0 runtime-delta; toggle manual/owner-driven by design) — bites only when Fable returns + tiering resumes. **Anti-pattern: mirror-a-toggle copies the WRITER side but silently drops the READER side** — a persist-claim needs BOTH write-on-set AND read-on-session-start; verify the consumer exists, not just the producer. Vacuously-met disclosure itself was clean (§K.D + mark both say "KHÔNG overclaim runtime-delta"). *(dời từ Role-baseline @S102 — H2 Placement-flag; NOTE @S102: reader BƯỚC 0.5b ĐÃ wire tại S101-cuối → CONCERN closed, marker có consumer.)* - **S100 H18 WF2 synthesis + Lane-B** — SYNTHESIS reviewer 2-lane JSON→overall **PASS_WITH_CONCERNS** (LaneA PASS + LaneB PWC, neither BLOCKING). Re-verified indep: ledger +2/0-del revert-clean · ratio-band replaced `|diff|>=10` · glob replaced 3-fixed-list · 6/6 consumers 🧊-marked · every LIVE `_ledger` marked (unmarked=history) · CONCERN workflows/README:51 no-token points-authoritative=non-block · KEY anti-pattern HELD (stale WF2 `wf_31ea3985` NOT stamped, both placeholders await fresh run). Prior S100-bis Lane-B PASS (2 minor) folded in. - **2026-07-10 (S108 first-real-run H19) `[engine: fable-real-single · Fable-S108]`** (em-main harvest B3, GAP-2/3): Task single-deep-pass adversarial 3 artifact S108 (runbook 58.7KB + adap-request + email outward — $outwardFlag=Y Cat-6). Verdict **FAIL** — 1 CRITICAL (email claim “đã sửa comment” khi hmw.js:31-32 chưa sửa, cat xác nhận) + 4 MAJOR (2 stale-outage-claim sót §3.5/§4.3 · clone-example thiếu tier:'opus' trái K.B/floor-2 khi Fable UP · AP-4 tự-toggle trái K.D-2 · drift-note 9-vai sai vs engine-10) + 6 minor; core JSON-shape/biến/checklist/GAP-guard **SOUND** (7 refutation: 5 đứng · 2 vỡ về phía artifact). Learned: doc assemble-từ-N-worker → grep stale-claim theo CLASS toàn file sau khi fix đại diện (header “đã sửa 6” ≠ sửa hết) · mọi outward-claim “đã sửa X” phải cat X trước gate. Surprise: đoạn drift-note (viết để cảnh báo drift) là chỗ duy nhất mô tả sai canonical. Em-main áp 37-fix + vá hmw.js thật → verdict-fixes closed cùng phiên. Return dòng-1 Verdict-header chuẩn, 0 garble. --- ## S112 curate (self, 2026-07-12, hook 20.5KB) — collapsed 2026-06 digest cluster from L1 Recent-activity (verbatim below; detail already in 2026-06.md / linked area files) - **2026-06-29 S93 Harness-16 MFE adoption review (WF2 `wf_13e3d35a` 3-lane PASS 0-blocking):** ⭐ code-gate re-derived denom-29 + leading-verb-trap DEFEATED (`NEVER commit push`→0 content-word) + READ-ONLY-budget proof (1 write-op `.mfe-state.json`); WF1-reviewer caught BLOCKING vocab-fork (memory-fidelity H6.7≠H16 → MFE+alias-map §H). Detail → adap-report harness-16-mfe. → _INDEX. - **S92 (2026-06-29) Adversarial PROD-security hide 5 menu-groups admin-only on eoffice (uncommitted) — PASS (0 blocking, 1 awareness note):** A-E all upheld; CatalogManager Danh-mục access stripped (intended-by-spec, role assigned to 0 users post-S89, flag em-main only). Detail + per-attack file:line → project_s92_admin_only_modules_revoke.md. - **S91 (2026-06-25) PE D2 create-contract 1→N multi-winner + winner-names (FROZEN, NOT-deployed) — PASS:** fix for S89-bis dead-end; codegen mid-loop SaveChanges flushes ONLY seq-row (contract built LOCAL); GiaTri per-winner Quote-sum join PES.Id; positional DTO arg-order verified 3 sites; FE mirror byte-identical; 419 PASS. Detail → `archive/2026-06.md`. - **S90 (2026-06-25) PE stability-fix batch D1 (5 chg+11 test, FROZEN) — PASS:** Block B re-key SelectedSupplierId→IsWinner (single unchanged proven); CEO-notify SaveChanges (was Add-but-never-flush); HoSoLink null-safe+clear-via-empty option(b); #70 ||peFetching 2 PRO cells; 413 PASS. Detail → `archive/2026-06.md`. - **S89-bis (2026-06-25) AREA-6 FE-consumers (PE FROZEN, investigator verify) — 4/4 confirm + 1 NEW miss:** all 4 hold; NEW catch = create-contract joint-winner DEAD-END (FE shows button on `some(isWinner)` but BE hard-blocks `SelectedSupplierId is null`). Anti-pattern: single→multi conversion stops at detail-display layer. Detail → `archive/2026-06.md`. - **S89 (2026-06-25) AREA-4 workflow-edit (PE FROZEN, investigator verify) — 3 confirm/1 do-not-touch:** HoSoLink #73-class clear-on-partial-edit CONFIRMED + NEW 2nd destructive call-site (PeDetailTabs:817 InfoTab.save omits hoSoLink). Anti-pattern: echo-all-siblings convention rots when NEW absolute-set field added. Detail → `archive/2026-06.md`. - **S86 (2026-06-24) PE Section B 3-cột Dự-án|PRO|CCM (Mig 59) — PASS:** authz byte-mirror UpdatePeSuggestedPriceCcm (NotFound→Forbidden, fail-closed); FE `canEditCcm` KHỚP BIT-EXACT BE gate; submit-guard untouched (grep CcmBudgetPeriod in Services=ZERO); div-by-0 safe; 402 PASS. Detail → `archive/2026-06.md`. - **S82 (2026-06-21) Harness-15-v2 adopt review (0 code) — 3/3 lane PASS:** caught 3 MINOR. Memory-note: `broadcasts/_index.md` sha = notify self-declared `content_sha256` frontmatter NOT recompute → don't flag index-vs-file mismatch before reading frontmatter. Stamped-mark mid-session edit OK if only refresh confirmed-decision What-cell. - **S76 (2026-06-19) PE budget 3-cột Mig 56 + badge — PASS:** MAJOR race fixed gotcha #70 (useIsFetching gate). Badge role-set MUST mirror gate bit-for-bit. SURPRISE: spec "KHÔNG migration" FALSE — đọc changed-set thật, đừng tin scope-framing em-main. → _INDEX S76. - **S72* (2026-06-18) Mig 54 PE giá-đề-xuất + CCM-finalize OPT-IN — financial go-live PASS:** fail-closed guard throw BEFORE set Phase=DaDuyet; finalize-bypass = 3 orthogonal gate + server-recompute amount no-trust-client. → _INDEX S72*. - **S71 (2026-06-18) Harness-10 run-trace — PASS/GAPS:** "TRACKED" 2-level = check-ignore(eligible) vs git-ls-files(committed), model only post `git add`. → _INDEX S71*. - **S69 (2026-06-17) Office re-skin + golive authz — PASS:** re-skin proof = grep api-call+queryKey sorted -u byte-equal; public-grant = granted root NOT inherit-root (no sibling cascade); accent missing -800 stop = silent no-class Tailwind v4. → _INDEX S69*. - **S65 (2026-06-16) public HRM Hồ sơ + PE mục E — PASS:** upgrade-path MUST MUTATE row (`if(!row.CanRead){...}`) NOT skip-existing when prior revoke pre-set false (S58-class); menu-hide ≠ API-lock. → _INDEX S65*. - **S88 (2026-06-25) Fidelity-gate L2 gist distill (test-specialist) — FAIL (1 fabrication-by-merge):** gist gán "Mig 45" cho cluster span 2 episode khi chỉ 1 mang số đó (Master = Mig 47). Anti-pattern: merge-distill fabricates false specificity; token-PRESENCE pass BLIND to cross-episode mis-attribution → QUALITY gate after presence gate. Detail → `archive/2026-06.md`. - **2026-07-12 (S112 Supplier Excel-import Phase-B close-review, FE/E2E/DEPLOY lane) `[fable-real-single]`:** **GO-WITH-ADJUSTMENTS** — detail → `project_s112_supplier_import_review.md`. Mandatory known adjust = bake ExpectedHeaderTokens (svc:35-67); MAJOR independent catch = FE Import button reuses Suppliers.Create guard but endpoint needs Admin/CatalogManager role → non-functional button for fe-user drafters (BE secure). Deploy dup-risk CONFIRMED safe (4 real NCC ungated-seed Codes=col4 → re-import Update/fill-nulls). Lesson: reusing sibling menu-guard for Admin-scoped NEW action under-restricts — derive guard from ENDPOINT authz. Positive: 24 clamp-consts=EF-len byte-exact, int-enum contract exact (no StringEnumConverter), multipart matches 4 working uploads. - **2026-07-12 (S112 PE sign-off approach-review PRE-fan-out+deploy, security/governance lane) `[fable-real-single]`:** **GO-WITH-ADJUSTMENTS.** (1) EDGE-5 decision-3 hard-lock: spec placement (reject-branch SVC:92 + EnsureCanReject:321 + handler) **INCOMPLETE — bỏ sót admin-override path SVC:290** (`if(isAdmin) evaluation.Phase=targetPhase`) → admin un-terminal DaDuyet bằng decision=Approve (KHÔNG qua reject). Fix = 1 guard TOP-of-method sau `var fromPhase` SVC:53. Lesson: **terminal-lock gác FROM-state ở ĐỈNH method, KHÔNG rải per-branch** (per-branch bỏ sót admin/fall-through). (2) CEO-skip decision-2: A1 (creator tự ký ô mình thay auto-bypass) **TẠO đường CEO-skip MỚI** multi-step-có-CEO — trước A1 bypass advance-qua slot creator (bỏ check finalize); sau A1 creator qua ApproveV2Async → slot có `AllowApproverFinalize`=true + tick → DaDuyet bỏ CEO (SVC:867). invest-C "đã tồn hôm nay" IMPRECISE (chỉ đúng 1-step-no-CEO). Escalate owner. Lesson: **đổi auto-advance→manual-approve = mở lại per-slot flag mà auto-path che khuất** — re-scan flag khi đổi ai-đi-qua-code-nào. - **2026-07-12 (S112 Supplier Excel-import close-review PRE-deploy, BE+ADJUST) `[fable-real-single]`:** **GO-WITH-ADJ.** 6 axes PASS: OrdinalIgnoreCase preview+confirm (BuildCiIndex:446/batchByCode:157/seen:158), FillNulls:381-409 skip Code/Name/Type, all-or-nothing gate:137-152 pre-mutate + SaveChanges:188, parser abs Cell:284 (KHÔNG CellsUsed) +#REF!→null:289 +NAS-raw:290 +fingerprint-Ordinal-reject:223, Mig 63 reversible+3-file+snapshot:3330, col→field 30/30 OK (Code=col4 viết-tắt, Name=col5 tên-cty). REQUIRED adjust = bake 30 real token → ExpectedHeaderTokens:37-66 (nguồn test RealFileHeaderTokens:420-451 == brief exact; Case 9 auto-flip). **CAUGHT (MAJOR de-risk): Unicode NFC/NFD** — test dựng workbook từ literal NFC nên KHÔNG chứng file Excel THẬT accept; đề `.Normalize(FormC)` NormalizeHeader:306. Lesson: self-flip token-test = internal-consistency KHÔNG external-file-acceptance (artifact ngoài repo = bất-khả-verify). - **2026-07-12 (S112 FINAL pre-commit+deploy review — BÓ 2-feature PE-signoff + Supplier-import) `[fable-real-single]` — VERDICT GO (0 must-fix):** Cả 2 close-review adjust ĐÃ áp đúng. **F1 PE**: EDGE-5 guard đúng ĐỈNH-method SVC:66 (sau fromPhase:53) exempt admin+system, precede CẢ 5 branch incl admin-override:306 (:306 vốn `if(isAdmin)` nên non-admin không tới) + EnsureCanRejectV2Async:332 untouched; A1 minOwn=Min(Order):607 bypass1)`:637 (StepIdx giữ 0 từ submit:265), 4 nhánh cũ (auto-sign/next-Bước/step2/terminal) DELETED; History CHANGE4:751-777 log opinion-cũ→Changelog TRƯỚC 4 dòng overwrite, chỉ non-empty, keyed per-level-row (matchingLevel.Id) → chỉ fire khi CÙNG-NV re-sign, enum Workflow=5/Update=2 tồn. Tests 8-new/4-updated adversarial-grade (EDGE-5 system-exempt chứng qua msg "không hỗ trợ"≠"kết thúc"; history 2-boundary). **F2 import**: 30 ExpectedHeaderTokens==test byte-identical all-NFC (script verify 0-mismatch); NormalizeHeader FormC:313 áp cả 2 phía; endpoint [Authorize(Roles=Admin,CatalogManager)] = pattern Update/Delete; Mig 63 = 2 nullable additive (prod-safe, expansion-cols từ Mig 62 `778fc98` deployed per 4-NCC-in-prod). **Nice-to-have (KHÔNG block)**: (a) test comment :31-37 + svc :31-34 stale "BEST-GUESS chưa khớp" (đã bake) — misleading, harmless; (b) test NormalizeJoin:407-414 thiếu `.Normalize(FormC)` mà svc:313 có — moot vì token toàn NFC nhưng latent nếu sau thêm token NFD. **UAT-visible behavior change (by-design, không phải bug)**: A1 bỏ auto-terminal-on-submit → TP tạo phiếu-1-bước-tự-là-cấp-cuối GIỜ phải bấm Duyệt thêm 1 lần (trước tự DaDuyet). **Lesson: Case-9 self-adjusting (shouldMatch tính runtime) PASS ≠ chứng real==expected → phải diff byte-level 2 mảng token TAY; build/test-green (458) nhận theo claim, review logic bằng đọc.** - **S115 (2026-07-13) `/fable-real` spec-review presence-not-age adopt (D1 docs + D2 hmw.js STOP-HARD + D3 archive-gate) — PASS-WITH-FIXES (0C/2M/5m):** sub = `runs/2026-07-13-presence-not-age-adopt/spec-review-fable-real.md`. **M1: acceptance-grep can't detect its OWN deliverable's miss** — D2 crit-4 regex `fail-soft.*default subagent\|degrade về default subagent` catches only 1/3 doc-lines (misses ultra-on:21 "cảnh báo" + README:208 order fail-soft-AFTER) → 0-hits=false-PASS; fix = bare-token grep + human-classify vs frozen-history, NOT narrow ordered-pattern. **M2: "skip element" bolted on contiguous-prefix cut = correctness inversion** — naive `if protected continue` leaves skipped entry ABOVE cutLine → STILL archived while code thinks excluded; needs non-contiguous per-entry byte-sum; DRY-RUN bounds harm but 0 acceptance tests after-est. **Lessons: (1) `parallel()` = runtime-builtin NOT in-repo → premise unverifiable-from-source but design robust-under-BOTH-truth-values = endorse-with-caveat; (2) grep-acceptance must bare-token+classify; (3) verify EACH regex-alt vs EACH real target-line by hand; (4) node --check HAS teeth + top-level return/await pass via CJS wrapSafe (empirical > theory).** Spec faithful (3 floors+rec-3+3 honest-notes verified on-disk), scope-clean, honest-caveated; no Smart-Friend lower. - **S116 (2026-07-13) outward-email GATE se→ai_infra H-22 WAL restart runtime-verify — PASS (0 over-claim / 3 minor):** file `broadcasts/outbox/ai_infra/2026-07-13-se-to-ai_infra-h22-wal-restart-runtime-verify.md`. 6/6 ground-truth re-run MATCH — #1 rev-list=0 · #2 tree clean (modulo email-artifact itself untracked) · #3 HEAD=88bd8e6 · #4 WAL empty-template · #5+#6 EXACT: archive-gate 12/12 sub<25.6KB (tightest investigator-codebase 25237, 363B headroom) + A7 246/246 pointers 0-fail; crystallized 382713B/380K-tok cap/252429-tok headroom. Caveat section STRONG+prominent (own §header "Nấc honest", bold WAL RỖNG/CHƯA, enumerates a/b/c verified vs content-recovery NOT; line31 defers real-persist→S111 Stop-hook×2). No implicit "full restart-recovery verified". **Minor: (1) caveat item (a) "WAL persist qua restart" evidentiary-WEAK — `.claude/WAL.md` git-COMMITTED @88bd8e6 empty-template 0-drift → post-reboot existence = git/filesystem guarantee NOT WAL-mechanism proof (self-corrected by line31 defer-to-S111); (2) unit-notation "382.7KB / 380K-tok" juxtaposes bytes-vs-tokens (382.7KB≈95-127K tok not 382.7K) — looks scarier/understates headroom, "(fits)+252K" resolves; (3) current tree clean modulo email-artifact-itself (untracked).** Lesson: persist-claim on git-tracked WAL → verify tracked+0-drift FIRST; "file survives restart" = git/filesystem property, mechanism-persist proof lives at Stop-hook run (S111). No Smart-Friend lower — report well-calibrated toward humility. - **S117 (2026-07-13) PE negative-quote FE-only spec-review (financial-invariant-owner lens) — PASS (0 blocking, 1 confirm + 2 test-notes):** budget-intact VERIFIED — UpsertQuote (`PurchaseEvaluationDetailFeatures.cs:282-366`) writes 0 budget fields; quote ThanhTien flows ONLY into read-only display aggregates (currentProposalTotal/prevSelectedTotal :911-926 + winnerQuoteTotal :1188) — NEVER mutates PeWorkItemBudget. #81 IsWinner + S114 multi-winner SAFE: winner-derive keyed on `IsSelected` boolean, sign-agnostic (negative ThanhTien irrelevant). R1 baked (ContractFeatures.cs:46 GiaTri>=0 untouched=manual path; CreateContractFromEvaluation:88-90 no-clamp=PE-inherit). R2 FE:201/BE:206 BOTH `SUM(ThanhTien where IsSelected)<=0` = IDENTICAL algebraic sum → 0 divergence from negatives. CONFIRM raised: enterable-negatives OPERATIONALIZE net-value driving CEO-escalation gate (winnerQuoteTotal0 submittable" half needs multi-quote seed. **Lesson: 2-tier guard divergence check = compare SUM EXPRESSION not just comparator; derived-flag safety = trace what flag is KEYED-ON (IsSelected≠ThanhTien); "budget intact" true for RECORD but quote-sum still flows to display+governance aggregates.** ## @S126 hook-curate batch (2026-07-16, em-main single-writer, moved-not-cut verbatim từ L1) - **S124 (2026-07-15) adap-wave-reply PLAN L3-lens — PASS_WITH_FIXES (0C/3M/2m):** disk `sub-reviewer-3.md`. 🎯 **do-token trap committed WHILE adopting do-token**: spec "STATUS=26075 tok (real-N)" — I re-Read FULL → truncation = **70892 tok** (tail-alone 33944 > 26075) ⇒ near-cap CHUNK mislabeled whole-file, 2.72× under, feeds owner re-tier. **Lesson: verify do-token claim = re-Read full + read truncation line yourself; token count tokenizer-invariant ⇒ 2×+ gap = mis-measure not env.** M2 meta-count "6 R1-R6"→5 (R5 highest-value dropped). M3 nấc "verified" on cadence NEVER-RAN (hub-expected = "đã đọc không đổi"). Positives held: authority-class owner-gated correct · harness_floor 55K self-audit honest · all-inherit 14/14. Anti-garble: full disk-write BEFORE return. - **S125 (2026-07-16) do-token RELABEL correction (em-main on-behalf, B3 append):** negative-control 3-probe (`'a'×150K`→notice "150,006 tokens" ~1,0/char · `'x'×150K`→150,006 Y HỆT content-independent · mixed-ASCII 150K→143,251 ~0,955) ⇒ **notice-N = heuristic họ-đếm-ký-tự = CẬN-TRÊN bảo-toàn, KHÔNG phải real-token** (tokenizer thật nén chuỗi lặp ≪0,1/char). 70892 (dòng trên) đọc lại = cận-trên; dải thật STATUS [31K byte/4 — 70,9K notice]. **Lesson sửa-frame: "token count tokenizer-invariant" chỉ đúng cho so-sánh chunk-vs-full CÙNG heuristic; nhãn "real-N" tự nó = mislabel-as-real — phải negative-control (chuỗi lặp) mới phân biệt heuristic/tokenizer.** Nguồn: hub `phuong-phap-dem-token-tien-de-vong4` + adap-report cùng tên. - **S125 (2026-07-16) fable-real adap-review — PASS-WITH-SELF-FIXES [engine:fable-real · vai compound anh gán reviewer+inv-cb · inline-lead]:** 2 near-miss TỰ BẮT trước khi ra ngoài: (1) **false-TAMPER → RCA verifier**: PS 5.1 `Get-Content -Raw` decode UTF-8-no-BOM bằng ANSI → mojibake → hash sai trên broadcast hub SẠCH; **sibling-test 2 CHIỀU** — sibling-MATCH⇒file-bệnh (tiền lệ S100) · sibling-CŨNG-FAIL⇒**verifier-bệnh** (S125); chốt bằng `stamp_verify.py` hub exit-0. (2) **suýt claim-sai nguồn outward**: draft adap-request viết "snippet hub dùng Get-Content -Raw" — mở hub `check-email.md:18` thì snippet **để HỞ decode** (`$txt` không định nghĩa) + hub ĐÃ CÓ s76 script-verify → sửa email+request TRƯỚC stamp cuối; email edit-sau-stamp → **RE-STAMP** `58f5afd8` + selftest exit-0 ×2. **Lesson: outward-claim về văn-bản bên kia = mở ĐÚNG file+dòng trước khi viết; email đã stamp mà cần sửa = sửa→re-stamp→re-selftest cùng lượt, đừng để stamp-then-edit sống.** Bẫy tooling: Edit-tool 3× fail chèn escape BOM (pipeline sinh-chữ render escape thành U+FEFF thật) → build-from-codepoint. Evidence: `runs/2026-07-16-S125-fable-real-adap-review/`. ## [S128 curate batch — moved verbatim from L1, 2026-07-16 em-main] - **S124 L2 fidelity-to-source review, adap-wave plan — PWF (0 misread/1 MAJOR/3m):** 5/6 broadcast-reading traps read-faithful (NOT-adopt→method/spirit · h17 4-floors-KEEP · r6 abs-path). MAJOR = **push-guard "REFINEMENT ahead-of-broadcast" (spec:58) = OVERCLAIM**: SE trailing-K is LOOSER than broadcast ahead-range-all-count, keeps sandwiched wal:→leak; NO dimension strictly ahead. run.md:15 + mark cl.4 already carry honest "noise-accepted no-rewrite" ⇒ spec contradicts own run.md+mark. **Lesson: "ahead/refinement" = verify vs broadcast's ACTUAL requirement (looser≠ahead); spec+adap-report = shipped artifact → reconcile before hub-send.** Verified: adap-reports at `docs/governance/` not `.claude/` (path-trap false-empty). → `archive/2026-07.md`. - **S112 fable-real-single close-reviews+FINAL — GO 0-must:** Import btn reuses sibling-menu guard but endpoint=Admin ⇒ derive guard from ENDPOINT authz; EDGE-5 gác FROM-state ở ĐỈNH method KHÔNG per-branch; self-flip token-test = internal NOT external-accept. → [topic](project_s112_supplier_import_review.md). - **S126 (2026-07-16) A1-H23-probe + email-H23-gate [opus ×2, em-main VERIFY+APPEND] — gate FAIL bắt 3 lỗi thật trước stamp:** (1) 🎯 "Audit 2/2/0" NON-REPRODUCIBLE — audit COUNTS = **session-cumulative**, chính 2 lane review đẩy 2→4. **Lesson: số AGGREGATE cumulative KHÔNG vào outward artifact mời-reproduce — evidence bền = per-lane theo run-id.** (2) "Ba việc nêu ở thư" thực = **2 ASK** — MỞ thư đếm ask thật, đừng gộp courtesy-expectation. (3) "hub 17/17" = SE-self-obs R1-open → hedge+quy-thuộc. Lõi verified độc-lập: lead=Fable **116/116** records · A1 fable · A2 opus. Fixed → stamp `945cf3ad` selftest+stamp_verify+_index CÙNG lượt. Evidence: `runs/2026-07-16-S126-adap-spec-execute/`. --- ## [BATCH S134-curate 2026-07-17 — moved verbatim từ L1 MEMORY.md (hook 21.3KB→<17.1KB), move-not-cut] - **S131b (07-17) GATE#2 outward email-hub closure-cadence follow-up (owner-direction narrate, KHÔNG claim đo mới) — PASS_WITH_FIXES (0C/1M/3m):** owner-fidelity vs 2-lượt-chat: "owner tự chỉ ra trade-off" phương-án-A = ĐÚNG (turn-1 owner nói CẢ pro 'giảm nặng start/end' + con 'khó theo dõi hơn' — reviewer NGHI bịa nhưng thật-sự faithful, KHÔNG manufacture) · 4 tiêu-chí trực-tiếp turn-2. 🎯 **M1: "nghi-thức chạy tắt HÀNG LOẠT" inflate source chính-xác "3 closeout liên tiếp"/3-session** (morning e46863c8 GAP-2) — re-introduce đúng overclaim-class mà morning-gate ĐÃ gỡ (2 fencepost/overclaim); follow-up outward tới bounded-source phải GIỮ con-số của source, "hàng loạt" undo kỷ-luật source đã trả-giá. m2: title quote "không **sót**" nhưng owner viết "ko **xót**" (x) — silent spelling-normalize + gloss "im lặng phải khác sạch" commit 1 reading của homophone mập-mờ; interpret probably-correct NHƯNG gate-prompt CŨNG lặp "sót" ⇒ divergence sót upstream = independent-catch. m3: paren-gloss 4 tiêu-chí trộn framework-lead vào section "Owner nhận-định" (hedged caveat-3). Số verify sạch: 250-300K=(ước lượng vận hành)✓ · 6/15 owner-decisions-file+memory-budget:122-123 ⇒ 'số owner đặt' ĐÚNG · eval~0 memory-budget:44 'deterministic NO-API analyzer' ✓. Caveat-block 3-điểm mạnh (chưa-chốt/est-spawn/SE-diễn-giải). Lesson: **verbatim-quote owner = so TỪNG CHỮ kể cả homophone x/s; "đã đo" outward chỉ pass khi trỏ disk-measure thật (morning email có).** - **S131 (07-17) GATE outward email-hub + adap-report §6 báo 3 op-gap H24×H22×H1/H2 — PASS_WITH_FIXES (0C/2M-shared-root/3m):** → [topic](project_s131_h24_h22_3gap_outward_gate.md). MỌI số atomic reproduce (counter=7·S124=3·S128/129/130 no-tick·tick chỉ session-start §2.1.8 [session-end §L.b(j) chỉ ĐỌC]·12 measured·9+4+1 flag·§5(a) flip đúng). 🎯 **Bắt fencepost khi số atomic ĐÚNG HẾT:** "8 nhãn/+4 (3→7)" ghép lệch cột-mốc (8 nhãn↔+5 baseline post-S123=2; +4↔7 nhãn baseline S124=3) → đọc 8−4=4-miss SAI (thật 3) → đẻ "gấp-đôi" 2× overclaim (đo thật 8:5=1.6×). Lesson: hero-ratio phái-sinh re-derive từ raw, đừng tin phép-nhân tác-giả; fencepost = liệt-kê từng nhãn + đếm tay. - **S129 (07-16 đêm) REVIEW adap-errata-EOL 2-lane `wf_8a0249f6` — GO-WITH-FIXES ×2:** R0 re-verify **byte-exact** T0/T1 + bắt P1 writer-only = **NỬA-VÁ** (reader `mfe-eval.ps1:193` là read duy-nhất thiếu `-Encoding UTF8`, đang BOM-sniff; blob mang BOM thật `ef bb bf` — S87 consumer-sweep áp cho cả ĐỀ-XUẤT-VÁ, không chỉ code) + 2 presentation-gap (blob-mutation không khai · lợi-ích thổi khi porcelain vốn rỗng — S81 class). R1 adversarial: 4/4 cite exact + 2 quick-test **tự chạy lại = chứng không-bịa rẻ nhất**; tally "7/7 ADOPTED" = rung-flatten 4-gated/3-discipline (S122 memory≠enforcement); story T0 "+1 agent mới" BỊA (delta thật = `skills/README.md` ngoài glob, số scoped=39); on-behalf verbatim 0-miss (22/22+41/41). Cả 2 lane #53 khai-path-không-ghi → em-main scribe từ journal. Tag `[s129, review-adap-errata, half-fix-writer-only, rung-flatten, byte-exact-rerun]` - **S128 (2026-07-16) D-review 2-lane adap 16-07 [hmw reviewer opus-max ×2 · R1 tự-ghi sub-md, R2 return-only→lead scribe; em-main VERIFY+APPEND] — GO-COMMIT 2/2, 0 BLOCKER, owner-gated 0-diff CONFIRMED:** R1: 5 acceptance re-run PASS paste-thật · hash 7/7 recompute · 0 self-claim "verified" · M1 evidence-paste "tô-điểm" (`contextual_retrieval = False` khi lệnh chỉ in `False`) — soi literal-fidelity CẢ KHI giá-trị đúng. R2: email fact-check 7/7 · counter cumulative AN-TOÀN khi neo file persisted reproducible (≠ S126 self-mutating) · lineage "05-26" → git nói 05-22 `bf93abd` — lệch CONSERVATIVE ⇒ minor không blocker (**direction-of-error quyết mức lỗi outward**) · brute-force canonical-variant với known-good TRƯỚC khi phán tamper (recipe strip-1 vs strip-ALL: 2 biến-thể sống chung theo phía phát-hành — SE-set khớp strip-1, hub-set khớp strip-ALL). Lead fold M1+lineage 3-chỗ-cùng-lớp + re-stamp `c0ac7486447e`. Trace: `runs/2026-07-16-S127-adap-dot-16-07/{sub-reviewer-0,sub-reviewer-1,review-synthesis}.md`. Tag `[s128, d-review, direction-of-error, sha-variant-per-publisher]` - **S128 fable-real #2 re-review spec-execute adap 16-07 [0-garble ghi-đĩa-tăng-dần; em-main VERIFY+APPEND] — GO-WITH-FIXES 4 SHOULD-FIX/0 BLOCKER (cả 4 = lỗi verify-lệnh/scope-rơi):** F1 count-quên-README · F2 so `_index` bằng Get-FileHash = SAI-LOẠI-HASH (body-sha ≠ whole-file, đo `181a6d19`≠`f29247cf`) · F3 nén draft→spec RƠI item gated cả 2 lane · F4 future-claim S108. **Lesson:** lệnh verify trong spec = CODE chạy thử trước (2/4 sai thật) · bệnh encoding S125 ở CMDLET không ở shell (`Select-String -Path` đúng, `Get-Content` bệnh) · fold = disposition TỪNG DÒNG (S119). Full: `runs/2026-07-16-S127-adap-dot-16-07/sub-reviewer-3-verdict.md`. - **S127 fable-real #1 gate đầu-vào adap 16-07 [Fable ~62K tok 0-garble; em-main VERIFY 3/3 + APPEND] — GO-ADAP, BÁC claim hub "bản 2 duy nhất":** rag.json:26 override ACTIVE ⇒ bản 5 việc THẬT + bản 3 ≥2 hằng-số sống-bằng-nhãn. **Lesson:** hedge broadcast phải test bằng MỞ config THẬT · "already-aligned" tinh-thần ≠ luật · SE GIỮ counter đúng (điều-kiện gỡ không áp: 3 tick/2 ngày). Full + AC 8/8: `runs/2026-07-16-S127-adap-dot-16-07/sub-reviewer-1-verdict.md`. - **S133 (07-17) pre-commit review pe-budget-freeze [wf_f9c0b939-181, return sạch]:** VERDICT **PASS_WITH_FIXES** — 0 MUST / 2 SHOULD (CÙNG root #81 indirect-writer) / 2 NIT. ⭐ Catch giá trị nhất: literal-grep 4-site (`= PurchaseEvaluationPhase.DaDuyet`) PASS hết, nhưng grep `.Phase = ` lòi **2 đường gián tiếp bypass helper snapshot**: `WorkflowService:308` admin-override catch-all (`= targetPhase`) + `DbInitializer:1323` seeder (`= current`; fresh-DB migrate-trước-seed → backfill Mig 67 no-op trên bảng rỗng). **Bài: RULE "mọi nhánh set X" phải grep CẢ assignment-qua-BIẾN, không chỉ token enum — #81 mở rộng lên lớp indirect-assignment.** 10/10 mục PASS: 3-bản predicate khớp từng điều kiện (kể cả chi tiết Suppliers/Quotes = BaseEntity → SQL đúng khi KHÔNG có IsDeleted trên s/q) · 18-field frozen mapping chỉ rò đúng 2 field cố-ý (pairRec.Id + CurrentProposalTotal live) · R2-hold ✓ · guards đúng vị trí + T5/T6 ✓ · EDGE-5 snapshot-dormant + T9 overwrite ✓ · FE fallback `?? bs.*` nằm TRONG nhánh editable đã đóng ✓ · Mig: UNIQUE(ProjectId,WorkItemId) chống row-multiplication LEFT JOIN backfill ✓. Lead áp 2 SHOULD ngay trong phiên: site-5 helper-call + test `AdminOverride_DirectToDaDuyet_SetsBudgetSnapshot` + seeder demo snapshot + comment gate → suite 520/0. Tag `[s133, review-budget-freeze, indirect-assignment-grep, 81-class]` - **S123 governance 4-change review (backtick-guard + H24-3 + retire dạng-3 + mark) — PWF (3 must/1 MAJOR/3m):** → [topic](project_s123_governance_4change_review.md). 🔴 **#53 garble tại TAO; đĩa KHÔNG cứu vì chưa ghi diary ⇒ ghi diary TRƯỚC return.** Vá-1-lớp⇒grep MỌI matcher cùng-lớp TRONG diff · đổi-format-cho-trượt-mẫu = Goodhart rời-tập-đo. --- ## [BATCH S140-curate 2026-07-18 — moved verbatim từ L1 MEMORY.md (hook 20.7KB→<17.1KB), moved-not-cut] - **S139 (07-18) L3 review wave adap-3-bản 8-file [wf_65e5cf1e-397 · return CLEAN 0-garble — VERDICT-header-dòng-1 giữ đúng · read-only → EM-scribe sub-reviewer-0.md] `[engine: opus-worker]`:** **GO 0C/0M/3-LOW-nit** — re-measure MỌI acceptance từ git HEAD, không tin sub-0/sub-1/EM: L1 heading 26/28/7/14 HEAD==CUR + MASTER-CHECKLIST 1/2/1/1 + 10/10 config-token + 3 deletion content-preserving · L2 re-run fault-inject **C6 8/8 + H24-4 8/8 byte-exact** + live TOTAL=45/exit-0/2-net-0-flag + Test-Quoted CẢ 2 matcher mới (diff:143/:253) + code-point 0-literal-non-ASCII · 4 EM-edit đúng (reviewer.md ĐÚNG-1-từ +grounded — **m-3 no-self-exempt: chấm cả edit vào file CHÍNH VAI MÌNH**; "4 cấp mark" self-catch của EM ĐÃ GIỮ) · đảo-thứ-tự edits-trước-L3 = SOUND no-new-hole. Nits: sàn-5 vocab-collision session-end :72(🚩H22) vs :108(🔢S138) LOW owner-decidable rename/alias-map · mirror-C1 §2.1.2 thiếu `runs/*/run.md` (B1-pointer mitigated) · G-011 wording variance. Learned: **nhãn "measured" sống qua gate CHỈ KHI falsify-path tồn-tại VÀ reviewer CHẠY nó VÀ nó đứng** — 2/2 nhãn wave này grounded thật ("172/185 bare-cites" reproduce ĐÚNG TỪNG CHỮ SỐ bằng grep độc-lập; residual: counter không wired → drift-nit). Surprise: marker-collision M-1 là ca SỐNG trên docs/HANDOFF.md thật (:7 "Prev S134" giữa-dòng vs :9 boundary đầu-dòng) — fix `^`-anchor chịu-lực thật trên chính file detector đọc, không phải phòng-hờ lý-thuyết. Tag `[s139, l3-go, adap-3-ban, measured-label-grounded, m3-no-self-exempt, san5-vocab-nit]` - **S134b (07-17) pre-commit review lũy-kế tạm-tính [wf_8bb5abee-657 · ghi sub-reviewer-precommit.md — tên RIÊNG tránh đè sub-reviewer-0 của lượt fable-real] `[engine: opus-worker]`:** **PASS 0C/0M/4 nice-to-have** — 7/7 trục; diff +310/−25 (25 deletion = expand-chữ-ký tại chỗ, scope-drift 0%). Positive đáng nhớ: **bài #81 CỦA CHÍNH MÌNH (S133) được implementer áp đúng** — 5/5 finalize→DaDuyet qua helper (admin-override `:311` gate `targetPhase==DaDuyet` + comment cite #81), seeder `:1323` bypass CỐ Ý + set snapshot trực tiếp → 0 changelog D4 rác. Tự chạy lại build+npm×2+filter 8/8 (KHÔNG tin evidence cũ khi diff đổi). 4 nice-to-have = test-backlog: live-fill symmetric-C7 · admin-override D4-path · MaPhieu-null render · PendingSubmitted âm. Learned: (1) **"insertion-only + `grep '^-'`=0" đọc nhanh + chắc hơn diff-mắt** cho ràng-buộc bất-động; (2) D4-persist-path soi = trace TỪNG caller tới SaveChanges (5/5 có :301/:316), Add-không-save = row ma. Tag `[s134b, precommit-pass, 81-ap-dung, subfile-ten-rieng]` ## [BATCH S143-curate 2026-07-22 — moved verbatim từ L1 MEMORY.md (hook 26.5KB→<17.1KB), moved-not-cut] - **S141 (07-20) fable-real gate SPEC adap đợt-9/10 — GO-WITH-FIXES 0C/7M/9n `[engine: fable-real · model claude-fable-5 spawn-param-thắng data-point mới · wf_25210715-f7d · 0-garble, sub-file ghi-trong-lúc-làm]`:** spec-review 5-trục trên spec THIẾT-KẾ (chưa có diff) vẫn bắt 7M thật. ⭐ M3-class: **2 site roster-count sống nằm NGAY TRONG 2 file spec ĐANG sửa** (session-start:97 + session-end:142 "4 monitor") — 5-lane invest + lead đều sót vì grep token "roster 14" MISS site viết "10 … + 4 monitor" ⇒ **sweep same-CLASS (mọi cách viết count) không chỉ literal**. ⭐ M2-class: detector MỚI phải kiểm luật owner TẠI CHỖ trước khi quyết TOTAL (governance-detectors.ps1:65-68 "brand-new net → INFORM-sink day-one" — spec quyết ngược không reconcile). ⭐ M7-class: sửa prereq-stale (b) mà bỏ (a) cùng-đợt-về = tạo stale MỚI cùng class đang vá. ⭐ M1: FI ca "giảm-counter" bất-khả-FLAG nếu detector thiếu nhánh regress — acceptance phải falsify được TỪNG biến-thể. Fidelity-check 7 thư: FAITHFUL + 2 form-deviation có-chủ-đích (alias-model n1 · Light-skip M4 → carve-out-class cần lưới+khai-nấc). stamp_verify.py hub tolerant từ Jul-3 — thư 07-17 chỉ codify cái đã chạy. Tag `[s141, spec-gate, same-class-sweep, inform-sink-day-one, prereq-pair-flip]` - **S134 (07-17) SPEC-review pre-code PE lũy-kế — GO_WITH_FIXES 0C/2M/9N [detail → run sub-reviewer-0.md]:** M1 spec đặt "không đổi X" phải tự-kiểm mọi field bắt-buộc của việc-mới có đủ nguyên-liệu trong X-nguyên-trạng (helper thiếu actor param ⇒ hmw tự thêm = VỠ acceptance A6) · M2 claim-hành-vi-FE phải trace về biến trong predicate, không tin câu-văn · SHA 6-file TỰ-ĐO = trọng-tài khi 2 nguồn lệch (`47c97df1`→`5534addb`). Tag `[s134, spec-review, constraint-self-consistency, banner-gate]` ## 2026-07-17 S138 — review spec wave 3-bản (engine fable-real · **#53-GARBLE → entry ON-BEHALF, lead ghi sau VERIFY-đĩa** từ transcript-forensics `wf_a0aa62f5-9e8`) - **Task:** adversarial review spec v1 wave adap 3 bản AI_INFRA 17-07 — chạy 36 tool-use/208K tok, đọc TRỌN spec + sub-invest + 3 bản + 5 script đo + detector + 4 cửa + 5 re-count, **chết TRƯỚC khi soạn verdict** (StructuredOutput không gọi). - **Verdict (em-main-solo gate thay — KHÔNG phải phán của vai này):** GO_WITH_FIXES 3M/3m/1n; 2/3 MAJOR đến từ chính re-count của lane trước khi chết (HANDOFF:7 "Prev S134" giữa-dòng → boundary phải `^**Prev S` · STATUS In-Progress toàn lineage → scope HANDOFF-only). Chi tiết `runs/2026-07-17-S138-adap-3-ban-17-07/review-synthesis.md`. - **Learned:** wf-agent chết KHÔNG resume được SendMessage ("No transcript found") — thang recovery wf-lane = disk → journal → **transcript-forensics** → em-main-solo; re-count của lane chết = evidence dùng được. - **Surprise:** marker-collision — file HANDOFF hiện-hành chứa chuỗi "Prev S134" giữa dòng NEXT-anh ngay ngày detector được thiết kế (boundary-marker trùng mặt chữ nội dung, cùng họ citation-trap S123). ## 2026-07-18 S140 — FIDELITY GATE sleep-compress L2 (5 gist DRAFT vs verbatim, Phase 3b G-001 lead-no-self-grade) - **Task:** chấm 4-trục (bịa/drift/keep-drop/coverage-token) 5 cặp gist-draft↔`archive/2026-07.md` {cicd·tooling·inv-cb·harvest·reviewer} TRƯỚC khi lead Write chính thức. - **Verdict:** FIDELITY FAIL — 1/5 pair FAIL (**investigator-codebase**) + 4 PASS. inv-cb FAIL trục-3: "Drop thấp: 0" là CLAIM SAI — 2 recon-cluster verbatim THIẾU HẲN khỏi gist: line 31 S71 run-trace (`TRACKED`-2-level check-ignore-vs-ls-files · G-015 containment-shift H2→H10 · path-trap runs/22-tracked) + line 28 06-20 governance landing-map (`harness-11-engine` canonical D5-D10 · Harness-14 `keep_floor=5`/`golden-set`-14q). Grep độc-lập xác: gist 0-match cả 6 token, verbatim :28/:31 CÓ. Author gộp 3/5 sub-cluster của S125-batch (Office/PE-recon/FROZEN-Mig59) nhưng bỏ 2 → Drop-thấp overstate. Minor: 17.5KB(LIVE) mislabel self-target(thật 17.1) · AREA-2 `PeSuggestedPriceFeatures.cs:153-199` dropped. - **4 PASS:** cicd (20 run-record→6 CỤM; gate-chain Infra 413→464 / tổng 458→509 arithmetic khớp; A/005-008-010 + endsBeforeCeo flip exact) · tooling (12-dp model-chain + D-BUNDLE-lag + permission-matrix-Session6 exact; `D51OYyGV`/`BVdssm5S` nghi-bleed-từ-cicd nhưng THẬT ∈ tooling-verbatim :54 STATUS:27-pointer-history = 0-bleed) · harvest (7 block-md5: 5 khớp verbatim-header + 2 L1-only HONEST-disclosed ⚠; minor CỤM10 self-compact "S114"→thật @S113-end + list thiếu S123/S125-exec nhưng token-layer đủ) · reviewer (45-rec→9 CỤM, CỤM9=catch-all nên Drop-thấp-0 ĐÚNG; verbatim tự-lệch service:871-vs-873 → draft resolved-đúng-873). - **Learned:** "Drop thấp: 0" là claim FALSIFIABLE — grep từng June-recon-cluster curated-into-July xem gist carry chưa; 4/5 carry đủ (reviewer nhờ CỤM-catch-all), inv-cb chọn-lọc 10-nhóm bỏ 2 recon-infra mà vẫn khai 0. Per-file bleed test = token gist-X phải ∈ verbatim-X (không phải chỉ ∈ 1 verbatim nào đó); `D51OYyGV` cứu bởi pointer-history-line. Tag `[s140, fidelity-gate-sleep-compress, drop-thap-claim-falsifiable, inv-cb-fail-2-recon-cluster, per-file-bleed-pointer-history]` ## 2026-07-18 S140b — GATE OUTWARD email SE→ai_infra pre-stamp (G-015 no-overclaim, năm-vòng report) - **Verdict:** GO_WITH_FIXES (2 minor + 1 opt). Claim-by-claim vs đĩa/transcript phiên NÀY: **Vòng4** (fidelity 4-PASS+1-FAIL+CỤM11+grep-6-token-0-match) GROUNDED — gist committed `aa88d01` CÓ `## CỤM 11 :46` + 6 token `:47/:53` + Drop-thấp honest-disclosed (= CHÍNH việc tao lượt trước) · **Vòng5** (probe 5-nhãn `measured/empirical/calibrated/grounded/đã-đo` 0-tool 17s) GROUNDED = CHÍNH TAO + `lead-view-auditor:15` agentId `a56dcf6da…`+17s · **Vòng2** (light-audit#3 counter14 → 1 LOW view-stale + 1 MED gap-owner) EXACT = `lead-view:15`+`lead-omission:17` · last_sleep `07-10→07-18` EXACT (`aa88d01~1` vs HEAD) · `0b0285c` msg confirm H2 6/6+H1-1-drift · session-model-se-draft.md tồn (7779B). - **Fix-1 (precision/measured-label):** `68.968B` = DRAFT-total (reviewer draft 15777) nhưng SHIPPED `.gist.md`=**69175B** (reviewer +207 draft→final; 4 agent kia draft==final) · `183.054B` vs git-blob 183005 (<0.5%, CRLF/method). Honest-note (iv) đã round "≈183→69KB" ⇒ nới precise-figure về rounded HOẶC re-Get-Item final .gist.md. **Fix-2 (semi-overclaim):** "2 FLAG đều đã xử trong phiên" — diary: LOW=xong-chờ-closeout-clear · MED gap-owner-specifics resolve=PENDING (tracker/owner-defer) ⇒ reword "triage/nêu-hướng" chứ không "đã xử". **Opt:** `291550ff` (assert 2-chiều) = SE-internal hash, ai_infra khó resolve. - **Learned:** measured-label "68.968B" = draft-stage stale — số-đo phải trỏ artifact SHIPPED (committed .gist.md) KHÔNG draft-scratchpad; nhưng direction nhỏ (<0.5%, compression trông tốt hơn tí) + honest-note (iv) round sẵn ⇒ minor không FAIL (S128 direction-of-error). Outward-gate mạnh nhất khi claim = việc-CHÍNH-TAO (Vòng4/5) → re-measure by-construction. Tag `[s140b, outward-gate-go-with-fixes, measured-draft-vs-shipped, semi-overclaim-da-xu-pending]` ## 2026-07-22 S145b-curate — moved verbatim from L1 (S145a FAIL + S143 outward-gate); L1 digested to pointers - **S145a (07-22) gate GOVERNANCE-roster +1 vai-KIỂM `tooling-harvest-audit` (C4 TÁCH, adap dot-11, roster 17→18) — FAIL 3M/4m.** 🔵 Công bằng: CORE wiring THẬT tốt — role-file mirror `harness-audit` đủ (no-self-exempt m-3 · thách-CLEAN · tái-dựng ≥1 số CÓ-THỂ-SAI · fail-safe NO-OP · C4b mtime), session-end (g-bis) AUTO đúng (KHÁC (j)H24/(k)trio consent), STATUS 17→18 + cell + "Cả **7→8** monitor" + hmw.js VALID_ROLES (node --check OK) + dual-surface registry, axis 4 `verified-pending-restart` KHÔNG over-claim, axis 5 incremental (0 file h24-audit/sleep-audit). ⭐⭐ **CLASS MỚI = TÁI-PHẠM-BIẾN-THỂ của chính S141-S143:** wave đó giết NAME-enum blindness ("ĐẾM PHẦN TỬ đừng grep SỐ") — nhưng lần này drift chạy TRỐN sang **NUMERIC hardcode "roster 17"**: `fable-clone.md:3+:18` · `fable-real.md:3+:19` (argument-hint + heading, roster gồm monitor per `:21`) + `README:276` narrative → 4+1 site stale (→18). ⇒ **LUẬT: sweep repo-wide phải grep CẢ `\bN\b (folder|vai|roster|sub)` NUMERIC LẪN name-enum, KHÔNG chỉ site count-free mình sửa.** M-2 `harness-11-engine.md:345` name-enum thiếu vai mới + tự xưng "✅ VALID_ROLES = ĐỦ roster … trọn roster (14→17)" = ĐÚNG class `README:225` S143 (completeness-claim self-referential, đã update @S141 mà quên @S145). M-3 `README` skill-matrix `:186` thiếu row vai mới (trio có row từ S141). ⭐ **Measured-label gate BẮT:** WAL tự khai `doc-sync 8-enum … self-verify 0-stale` — "0-stale" là nhãn kiểm-chứng, FALSIFIED bằng grep repo-wide (self-verify chỉ scoped 8 site ĐÃ SỬA, KHÔNG repo-wide = đúng bệnh "sweep sạch sau khi grep subset" S143). 🔸 Pre-existing (phân-loại RIÊNG, KHÔNG tính lỗi change): `sleep-recovery-memory-l2.md:42` "4 monitor" thiếu CẢ trio (S141) lẫn vai mới (unmodified ⇒ predate) · `engine:332` GAP-1 lineage dừng S121 (thiếu trio). Tag `[s145a, governance-roster, enum-sweep-incomplete, numeric-roster-count-stale, name-enum-killed-numeric-survived, self-verify-0stale-falsified, core-wiring-clean]` - **S143 (07-22) gate OUTWARD wave đợt-9/10 (email ĐÃ GỬI + 7 adap-report) — FAIL 1C/4M/4m/1nit** `[#53 garble lượt-1 → vớt TRỌN từ sub-file; "ghi-đĩa-trong-lúc-làm" cứu lần 2]` — chi tiết đầy đủ → `runs/2026-07-22-S143-closeout-audit/sub-reviewer-0.md`. ⭐⭐ **CLASS MỚI `bằng-chứng-tự-huỷ-sau-squash`:** 5/7 report neo evidence vào `wal:` commit TIỀN-closeout (`1a0fa59`/`a458102`) → squash làm dangling (`branch --contains` RỖNG, `is-ancestor origin/main` exit 1) dù `cat-file`=commit ⇒ **hub không resolve nổi**; nội dung vẫn có trong `2757e41` ⇒ chết CON-TRỎ, không chết việc. Đối chứng: wave TRƯỚC cite `7760cdf`/`da349fc` (commit ĐÍCH sau squash) → sống hết. **LUẬT: cite trong outward = commit SẼ SỐNG sau squash, KHÔNG BAO GIỜ `wal:`.** Cùng class: `is-ancestor exit 0 → OK-reachable` lật exit 1 **trong cùng phiên**; evidence-paste `NHIP-NO … run-chua-gom 0` nay ra 4-vế. ⭐ **`git status --porcelain` là bước ĐẦU của outward-gate, không phải bước cuối** — lòi ` M scripts/nhip-no-probe.ps1` (+55/-2, mtime SAU push) làm SAI câu "**Chưa làm**, chờ owner" trong THƯ ĐÃ STAMP. ⭐ **Số publish phải neo mốc:** khai `TOTAL 46`, live **47**, baseline repo **45** ⇒ tách claim-DELTA (đúng, có Compare-Object) khỏi claim-TUYỆT-ĐỐI (thối theo giờ). ⭐ **Tái-phạm same-CLASS-sweep — bài S141 của CHÍNH TAO:** "TRIPLE 17/17/17" đúng ở `README:236` nhưng site tự xưng "VALID_ROLES … ĐỦ roster" (`:225`) còn **14** ⇒ chọn enum DỄ. ⭐ **First-person evidence:** frontmatter `reviewer.md` 0 `Write/Edit` mà **tao vừa Write+Edit thật** ⇒ claim "whitelist = tuyên-bố ý-định, không phải cơ-chế" GROUNDED. 🔵 Công bằng: **15/17 số tự đo KHỚP**, kỷ-luật nấc G-011 (0 thư khai `verified`) là hàng THẬT — lỗi ở lớp artifact, không ở việc. Remedy = **errata**, CẤM sửa file đã stamp (vỡ hash). Tag `[s143, outward-gate-fail, evidence-self-destruct-squash, cite-post-squash-commit, git-status-first, absolute-number-needs-anchor]` ## 2026-07-22 S145-curate (lane-4 self) — moved verbatim from L1 (S145 lane-4 Axis-D + S145 C7-lane Axis-A + S145b gate); L1 digested to pointers - **S145 lane-4 (/fable-clone Axis-D 5-vòng-closure) review SPEC apply-hub — PWF 2M/1m.** Owner-asked D2 RULING: DEFER (session-start KIỂM gap) LEGIT — canonical "hai đầu" nhịp binds MEASURE fn (H1 "báo diff vs last-session" session-start.md:127 ✓ both-ends + em-main VERIFY→APPEND B3), NOT the new KIỂM layer; canonical self-verify col V1/V2/V4 = CLOSE-time ("commit đóng phiên gần nhất"/"ba lần đóng phiên gần nhất") ⇒ 3 KIỂM session-END-only = canonical-CONSISTENT (arguably CORRECT reading). Contrast: harness-audit V3-KIỂM IS both-ends (consent). 🔴 **phép-4 LANDMINE live-on-disk (ESCALATE S145b minor→FAIL-risk):** `agent-memory/tooling-harvest-audit/` EXISTS-but-EMPTY + `h24-audit/`+`sleep-audit/` folders MISSING; tooling-harvest-audit AUTO-fires this close (session-end.md:118 no-consent) ⇒ run-mà-ko-write-sổ = phép-4 "vai-đã-chạy-có-sổ" FAIL NGAY closeout này. FIX-2: D1 "(bảng verify)" quá lỏng — phải SHOW per-check disk-evidence (cửa-count·dòng-nợ-line·3-closeout-trace·vai-sổ-list) ko bare "PASS". FIX-1: D2 "documented" unsatisfiable — spec route quyết cho lane-4 mà ko NAME nơi defer-rationale land (review ephemeral≠durable); +coupling h24-audit "AUTO sau H24" nhưng H24 chạy BY-CADENCE tick session-START §2.1.8 ⇒ cadence-at-open H24 un-audited. Root = session-end.md:123 "incremental #2/#3 land dần" MÂU-THUẪN :41-42 "AUTO wire cả 3". ⭐ LESSON: acceptance chứa "vai-có-sổ" ⇒ MUST `ls agent-memory//` on-disk (folder tồn-tại ≠ có MEMORY.md). Mapping 5-vòng→KIỂM verified REAL (7 agent files glob, ko doc-trust). Tag `[s145, fable-clone-lane4, axis-d, defer-ruling-legit, phep4-empty-folder-landmine-live, measure-both-ends-vs-kiem-end-only, canonical-self-verify=close-time]` - **S145 C7-lane (/fable-clone Axis A) — PWF, 1 CRITICAL conflation caught.** ⭐ Spec "đính-chính stale 4 surface→2" cho `nhip-no-probe.ps1:6-7` header = **FALSE**: verified 4 caller THẬT (`pause:44`·`tiep:112`·`session-start:216`·`session-end:104` — 3+4 là khối "BÁO dòng-nợ 4-vế" LIVE, KHÔNG deprecated); header TỰ-KHAI "4 surfaces (/pause /tiep session-start session-end)" = ĐÚNG. Spec-author **conflate 2 script cùng đuôi `*-probe.ps1`**: thấy session-start/end gọi `distill-shard-probe.ps1` (ĐÚNG, sleep-check `session-start:135`) → suy sai "⇒ KHÔNG gọi nhip-no-probe" (gọi CẢ HAI, khác mục-đích). `session-model-se-draft.md:34` "4 điểm lệnh" cũng ĐÚNG. **Acceptance A2 grep `"4 surface"=0-hit` = ANTI-TEETH Goodhart** — cổng PASS bằng XÓA info ĐÚNG, thưởng việc làm doc SAI (lớp "vá bằng rời tập-đo"). Fix = DROP step-4 + A2-stale-clause, GIỮ "4". LESSON: (1) "stale-fix"/"đính-chính" claim phải verify caller THẬT trên đĩa TRƯỚC khi tin — script header tự-khai caller-list = data-point **kiểm được**, đừng tin suy-luận spec-author; (2) 2 script cùng naming-pattern = conflation-vector, grep EXACT script-name không đủ, phải đọc caller-block xác mục-đích. Core C7 sound: law-home `engine §N` (không command, B1-point ✅) + fault-inject chiều-lỗi teeth (A3 falsifiable, minor=chốt inject-vector) + code KHÔNG đổi (catch:203-208 exit0 thoả vế-iv). Tag `[s145-c7-lane, conflation-2-probe-script, anti-teeth-goodhart-grep, header-selfdoc-verifiable, stalefix-claim-must-verify-disk, PWF]` - **S145b (07-22) gate GOVERNANCE-roster vai-KIỂM #2/#3 `h24-audit`+`sleep-audit` (C4/C4b TÁCH, roster 18→20) — PASS 1m.** ⭐⭐ **POSITIVE-VALIDATION: implementer VÁ ĐÚNG mọi finding vai#1 S145a + tự mở rộng sweep:** de-number `fable-clone/real` argument-hint+heading ("roster 17"→"roster"), fix `harness-11-engine:345` completeness-claim "14→17"→"17→20"+trọn-roster, +3 skill-matrix row, +3 decision-tree branch; PLUS tự tìm-diệt 2 NUMERIC site NGOÀI checklist (`vocab-alias-map` "17/17"→"TOÀN-ROSTER" · `README` auto-toan-vong "roster 17"→trỏ-canonical) = **bài "grep NUMERIC lẫn name-enum repo-wide" S145a ĐÃ NGẤM**. Axis4 CLEAN: STATUS 20 + hmw VALID_ROLES 20/20 (bidirectional cross-check mọi agent.md↔VALID_ROLES = 0 MISS) + README×6 + subset-enum-detector (đếm 1-2/3 per-line) xác nhận mọi ROSTER-enum FULL(3/3), 7 "subset" đều per-role hợp-lệ (decision-tree/skill-matrix/VALID_ROLES split 2-dòng). Role-file mirror đủ (RANH SẮC h24 "KIỂM con-đo H24 KHÔNG soi-lead trực-tiếp" · gist-ADDITIVE invariant · fail-safe NO-OP · JSON-pin THẬT: `flag_classes`=11/`h24_cadence`/`class_repeat` tồn-tại). Wiring: (ii-bis) AUTO sau cặp H24 KHÁC (ii) consent-gate H24 (khai thẳng, KHÔNG mâu-thuẫn) · Phase4.5 sau Phase3-Fidelity+Phase4-WRITE trước Phase5. Axis5 no-over-claim (executed/verified-pending-restart; counter "KHONG H24 audit phien nay"=khớp NO-OP). 🔸 **1 MINOR — measured-label gate:** `README:249` "cả 3 hiện chưa có folder ⇒ 17 folder vật-lý là đúng" FALSIFIED bằng `ls agent-memory/` = **18 dir** (`tooling-harvest-audit/` RỖNG tồn-tại từ phiên này); nhưng 17 dir CÓ MEMORY.md + git KHÔNG track empty-dir ⇒ committed-state=17 khớp enum ⇒ low-impact, fix=reword "17 folder-có-MEMORY". ⭐ **LESSON tự-thân: regex/bracket-count trên `hmw.js` VALID_ROLES DỐI** (non-greedy `[\s\S]*?]` + bracket-depth-parser CẢ HAI trượt vì `[2]`/`[S110` trong comment → báo "18/0" giả) ⇒ **đếm VALID_ROLES = per-file grep bidirectional (agent.md↔literal), KHÔNG regex**. Tag `[s145b, governance-roster-followup, PASS, vai1-lesson-absorbed, numeric+name-sweep-repowide, folder-count-vat-ly-falsified, regex-on-hmw-unreliable, bidirectional-crosscheck-wins]` - **S145 Axis-E lane (/fable-clone tiep/pause/snapshot + CROSS-CUT) review SPEC apply-hub — FAIL 2C/1M/4m.** Corroborated Axis-A lane CRITICAL independently: A.4/A2 "4 surface→2" FALSE (grep `scripts/nhip-no-probe.ps1` = 4 caller pause:44·tiep:112·**session-start:216**·**session-end:104**; A2 grep-0-hit = anti-teeth Goodhart). ⭐ **UNIQUE to Axis-E = 2 seam-catch 4 lane kia RƠI:** (CRITICAL-2 C↔E) Axis C.2 hook 3→4 path (+sessions/) phá Sàn-3 tiep.md §0 — "3 path"/"3 điểm mù" hardcode **4 site** (:21/:23/:75/:78); sau +sessions/ ⇒ (a) 4 stale, (b) BẬC-MẠNH signal④ chỉ phủ runs/ ⇒ sessions/ orphan KHÔNG signal = reopens "sổ trống≠sạch" blind-spot ON THE SAFETY-CRITICAL RECOVERY FLOOR, (c) BẬC-TRUNG :75/:78 "bẩn ngoài 3 path" misclassify sessions/-dirt (logic bug THẬT ko chỉ prose). Đã biết: adap-report 07-17:23 "meld-forward-gap (hook 3 path vs manifest 4)". Cả C.death-path(spec:33) lẫn E.death-path(spec:47) KHÔNG nhắc ripple = gap ĐÚNG khe 2 lane. (MAJOR-3) C.1 session_ctx_kb=64 nghịch owner-authority: 4 artifact phiên trước phân-loại OWNER-GATED + K6.2 CẤM "mượn số hub chưa đo" (session-model-se-draft:55); spec cite "canonical default" KHÔNG cite owner-directive + acceptance C1 ko đòi `_owner_set` lineage (bulk=30 CÓ); + **ghost-wire #H18: 0 script đọc session_ctx_kb** (pull_warn_days mà spec analogize thì CÓ reader nhip-no-probe:190) ⇒ analogy hỏng 2 mặt. ⭐ **LESSON cross-cut lane:** bất-biến chia-đôi giữa 2 axis (hook-path-count ⟂ Sàn-3-blind-spot-count) nằm ĐÚNG SEAM, mỗi lane-đơn thấy nửa → chỉ cross-cut sweep bắt; "áp hub-answer" (bulk/C7 hub-trả) ≠ "số owner-giữ" (session_ctx_kb SE CỐ Ý từ-chối) — đừng gộp. Tag `[s145-axisE, crosscut-seam-catch, hook-4path-breaks-san3-recovery-floor, session_ctx_kb-owner-gated+ghost-wire, corroborate-4surface-critical, FAIL]` --- ## @S155-curate (2026-07-27) — moved verbatim từ L1 MEMORY.md (hook 23.9KB → <17.1KB) - **[verbatim → git 8b6df0a closeout] S146 (07-22) PRE-COMMIT spec-v2-applied (governance 20 file) — 2 MAJOR THẬT (cả hai của LEAD); nấc `verified` tự-chạy-lệnh không-tin-lead:** F1 `session-end.md` còn `hook-3-path` GẠCH-NỐI dù worker CE đã chỉ đích-danh (class "residual có người chỉ tận nơi vẫn rớt") + bất-đối-xứng nội-bộ (`pause.md` đã 4-path). F2 phép quét cardinality của lead siết LỆCH-TRỤC (co-occurrence CÙNG-DÒNG + 1 mẫu-chữ) → re-run HEAD tiền-vá lọt 4 ca thật gồm chính F1. F3 HELD (git show da7ee8a: hook 4-path + `-File` re-đọc mỗi Stop). 🔴 Bài rút: lead sửa 1 phép quét 4 lần/phiên vì mã-hoá ý-định NGỮ-NGHĨA vào regex; nấc đúng = lưới-soát-cho-người + allowlist CÓ TÊN + use⟂mention; lần-4 = citation-trap (dò bắt chính nốt-vá vì nó trích giá-trị cũ). - **S147 (07-23) DIAGNOSIS-review PE attach TraLai (no diff — verify root-cause + stress fix) — Diagnosis PASS 5/5, fix CORE-safe/EXT-unsafe:** 5 claims verified from disk; BE-no-guard CONFIRMED **intentional** by S78 changelog L9 ("handler KHÔNG guard drafter-only → approver upload no-403") + sole pipeline behavior=ValidationBehavior. 🔴 **MAJOR blind-spot:** `attachEditable=isDrafter&&isEditablePhase` SAFE for GeneralAttachmentsSection (:2013 readOnly=raw, no carve-out) but UNSAFE for SupplierAttachmentsCell (:2758) whose readOnly=**itemsReadOnly** (`readOnly&&!approverEditMode`, Mig28-F3 ChoDuyet approver-edit) → naive REPLACE breaks approver QuoteDocument edit in ChoDuyet; SAME gap in optional BE guard (carve-out {ChoDuyet+ApprovalAttachment} misses ChoDuyet+QuoteDocument). **Scope trap:** isDrafter@:140 in MAIN scope, OUT-of-scope at :2013/:2758 (child comps take only {ev,readOnly}); changing :421 over-broadly hits HoSoLinkRow:2017. **Completeness:** WORKSPACE (readOnly=false, picker editableOnly∋TraLai) already edits comparison-doc in TraLai → bug is LIST-detail-only (:574/:669 hardcode). LESSON: **decouple a gate → trace if shared prop already carries a carve-out (itemsReadOnly ≠ raw readOnly); "same fix" for sibling surface may hit a DIFFERENT gate source.** ### S152 (2026-07-26) — D2 Fidelity-gate 6 gist "CỤM BỔ SUNG" (coverage-diff) — **PASS_WITH_FIXES** (A/B/C/D PASS · E FAIL) - **Census thay spot:** 307/307 trích có trong verbatim CẶP (275 exact + 32 sau khi hoàn `'`→`"`), 307/307 chứa ĐÚNG token gắn nhãn, 307/307 token thật-sự VẮNG khỏi gist tiền-append (0 gap thổi-phồng). `ref`=46 khớp đúng claim lead. Trích = cửa-sổ ~150 ký-tự cố-định, token ở ~27% → cắt giữa từ ở 2 biên nhưng payload (file:line/finding) còn nguyên ⇒ điều-hướng được, KHÔNG rác. - 🔴 **E FAIL — class-gap hệ-thống, chữ-ký sạch:** máy-trích emit file-ref CHỈ cho `{.cs 101/.tsx 45/.ts 16/.ps1 8}` = 170 token, **ZERO cho `{.yml,.json,.slnx,.csproj,.sql,.config}`** ⇒ 13 token infra vắng ở 5/6 cặp. Nặng nhất: `deploy.yml` (chính file pipeline, trong gist của vai CI/CD!) · `appsettings.Production.json` (16 lần trong verbatim) · 2× `s59-*.sql` (chạy TAY prod ngoài pipeline) · `memory-budget.json` (single-source canonical CLAUDE.md). Header cụm TỰ đặt chuẩn "file-ref phải sống trong gist" mà KHÔNG khai N/A ⇒ trượt bằng chính thước mình. - 🔴 **3 THƯỚC-HỎNG (bug ở phép đo, không ở vật):** (1) md5 disk vs `git show` — spec gate ghi vậy — báo FAIL GIẢ 3/6 verbatim do worktree CRLF ⟂ blob LF (autocrlf=true + 188 file legacy `i/lf w/crlf`); đúng phải `git diff HEAD --quiet` hoặc strip-CR 2 phía. (2) `grep -c distill-gen` vô-dụng vì CHÍNH header cụm chứa chữ "distill-gen giữ" (citation-trap nhẹ) → phải so VALUE `distill-gen:\s*\d+`. (3) `grep -iF` trên MSYS trả **0-hit im-lặng** cho pattern ASCII trong file UTF-8 (`Mig42`: `-F`=1 nhưng `-iF`=0) = bẫy vắng-mặt-trông-giống-sạch S146 — thoát nhờ đối-chiếu Python. - **Tự bắt 2 lỗi của CHÍNH mình trước khi báo:** "Mig 47/50/42/46 MISS" = artifact chuẩn-hoá của tao (`Mig42` liền không dấu cách, có ĐỦ 2 phía) · context-regex `.{70}` trả RỖNG đọc nhầm thành sạch → phải `.{0,70}`. ⇒ **LUẬT: mọi MISS phải literal-grep XÁC-NHẬN 2 phía bằng công-cụ THỨ HAI trước khi vào report.** - D re-ground từ đĩa: `docs/gotchas.md` count=83/max=83 ⇒ 0 nhãn `gotcha #N>83`; soi NGƯỢC 24 dòng gotcha ≤83 tìm mirror-error (run-number đội lốt gotcha) → 0 ca, mọi #N đều là gotcha thật trong ngữ-cảnh nguồn. Tag `[s152, d2-fidelity-gate, coverage-diff, extractor-ext-blindspot, thuoc-hong-x3]` - **S155 (07-27) DIFF-review đợt 1 tiền-DEPLOY (PE delete-approver, 14 FLAG 4H/6M/3L/1I) — DEPLOY-CÓ-RỦI-RO:** 🔴 **class MỚI `HIGH nằm ở git chứ không ở mã`** — 2/3 file migration UNTRACKED (`?? …AddPeAllowApproverDelete.{cs,Designer.cs}`) trong khi **snapshot đã tracked** ⇒ `git commit -a`/`add -u` nạp model-có-cột mà bỏ migration ⇒ `DbInitializer.cs:64 MigrateAsync()` không thấy gì để áp ⇒ `Invalid column name` cho **cả 7 module** dùng schema V2. Build+test đều xanh, local đã áp mig ⇒ **0 dấu vết**. **LUẬT: gate deploy phải chấm `git status ^??` cho `Migrations/`, không chỉ chấm diff.** · **H `ExecuteDelete` ngoài transaction TRƯỚC `SaveChanges`** = mất chữ ký không hoàn tác (đếm được **4 nguồn ném** nằm giữa 2 mốc ⇒ đường nổ có thật, không giả định) · **H purge xoá CỨNG chữ ký của phiếu mới XOÁ MỀM** ⇒ phá thẳng "khôi phục phiếu" của chính đợt 2; và **test `:607-609` đang KHOÁ chiều ngược** (`Should().Be(0)`) ⇒ cảnh báo trước cho wave vá: đỏ ≠ hồi quy, **cấm nới assert** · **H ~600 dòng BE = mã chết**: `grep api.put` = **0 hit**, Designer chỉ POST ⇒ đúng mục tiêu §F.0 (cứu phiếu đang treo) KHÔNG dùng được trong UAT. - **XANH-GIẢ bắt được bằng phép 2-thế-giới:** `F16_…NoPeChangelog` assert `PurchaseEvaluationChangelogs.Count==0` nhưng test seed **0 phiếu PE** ⇒ còn-gate và bỏ-gate **cùng cho 0** ⇒ phép đo không phân biệt được 2 thế giới = 0 thông tin. **Cách bắt: truy MỌI write-site của bảng được assert, rồi hỏi "bỏ guard đi thì quan sát có đổi không?"** - **CLEAN có răng (không "đọc thấy ổn"):** bất-biến Version/IsActive/Id chứng bằng **liệt kê vét cạn** `grep "def\.[A-Za-z]* *="` = đúng **3** write (Name/Description/UpdatedAt) **+ sweep gián-tiếp** (`= def;`/`SetValues`/`Entry(`/`CurrentValues`) = 0 hit ghi (hit duy nhất là READ trong string nội suy) — đúng lớp gotcha #81-EXT · **11 đường lách thử, tắc cả 11** · double-insert `DbSet.Add`+`nav.Add` = 1 entity, **và đã có test bắt nếu sai** (F12 assert đúng 2 row) · bán-kính đo NGƯỢC từ config: `grep OnDelete` ra **đúng 7** FK Restrict = khớp 7 bảng handler quét. - **2 lỗi CỦA CHÍNH TAO tự bắt:** (i) lần đầu trích line-number **từ diff** thay vì từ đĩa ⇒ sai toàn bộ, phải re-grep sửa lại (**LUẬT: `git diff` không mang số dòng file — mọi anchor phải grep từ đĩa**); (ii) `ls | grep -v Snapshot` **ăn nhầm** `AddPeApprovedBudgetSnapshot` ⇒ tưởng thiếu file migration — thoát nhờ đối chiếu `__EFMigrationsHistory` (S152 luật "MISS phải xác nhận bằng công-cụ THỨ HAI" ăn thật lần nữa). - **File bị sửa TRONG LÚC soi** (mtime lệch 71s — wave vá song song): anchor ≤`:659` giữ nguyên, sau `:660` trôi **+21**. **LUẬT: review file đang-được-sửa ⇒ ghi bản-đồ-trôi + neo bằng NỘI DUNG DÒNG, đừng chỉ số.** Tag `[s155, diff-review-pre-deploy, untracked-migration-gate, executedelete-no-tx, vacuous-test-two-worlds, anchor-drift]` - **S155 (07-27) SPEC-review tiền-hmw (PE xoá phiếu ở màn duyệt + lệnh Update workflow) — PASS-WITH-FLAGS 4H/8M/5L; spec trích-dẫn SẠCH nhưng 4 lỗ chí-mạng:** 🔴 **H1 class MỚI `nới-authz-mà-không-ai-có-quyền`** — spec gắn `[Authorize(Policy="PurchaseEvaluations.Delete")]` lên endpoint đang **KHÔNG có policy**; sqlcmd Dev đo: CanDelete=1 chỉ `Admin`+`DeptManager`, **11/13 role = 0** (`DbInitializer.cs:2515` `canDelete = roleName==DeptManager`, seeder-2 chỉ nâng Read/Create + skip-if-exists ⇒ prod không tự vá) ⇒ vừa **regression** (Drafter mất xoá-nháp đang chạy) vừa **feature chết** (Procurement 403). `MenuPermissionHandler.cs:41-51` khớp MenuKey **CHÍNH XÁC, 0 kế-thừa** — inheritance của `GetMyMenuTreeQuery` chỉ là display. **LUẬT: đóng API = phải đo bảng `Permissions` xem AI còn qua được; test-403 một-chiều luôn xanh-giả.** · **H3** `IgnoreQueryFilters()` **gỡ** filter chứ không đảo ⇒ list "Đã xoá" thiếu `.Where(IsDeleted)` + thiếu tái-lập IDOR `:596-617` = lộ toàn hệ. · **H2** cờ trên `ApprovalWorkflowLevel` = **1 row = 1 NGƯỜI**, repo có SẴN 2 idiom cho cờ anh-em F5 (`Service:859` per-row ⟂ `Features:1182` `g.Any()` per-Cấp) ⇒ "per-Cấp" trong spec = N người xoá được (owner muốn 1). · **H4** lệnh Update workflow không khai policy mà chính nó là **cổng cấp quyền** (thêm-người + bật-cờ). · **M1 phản-ví-dụ cho luật "AN TOÀN ⟺ giữ 2 tập Order"**: cờ `AllowApproverFinalize` đổi ĐIỂM KẾT THÚC phiếu đang chờ (`:859-878`) · `pendingLevelGroup.First()` (`:733-734`, tie **không có tie-breaker**) → thêm/bớt row cùng Order đổi slot chữ-ký Admin · thêm người vào Cấp ĐÃ QUA → `ComputeLevelStatus` thuần-con-trỏ (`:1135-1148`) hiện "Done" dù chưa ký. **⇒ con-trỏ-không-dịch ≠ phiếu-không-hỏng.** · **M3** soft-delete ⇒ cascade không chạy ⇒ `LevelOpinion` mồ-côi vẫn Restrict Level ⇒ nợ hoãn (N1) **ăn thẳng** vào luật mới F-5 cùng spec. · **M4** phiếu ChoDuyet chỉ vào **2/4** phép cộng ⇒ test "cả 4 giảm" bất-khả-xanh. · **M6** thêm key `Pe_*` **KHÔNG** đổi `Policies`/`Menu keys` (derived từ `MenuKeys.All`, `Pe_*` sinh factory) ⇒ spec bảo sửa số canonical = hỏng detector. **Cách phá F.0 (6 đường, tắc cả 6)** ⇒ mệnh-đề trung-tâm ĐỨNG, chỉ tiêu-đề rộng quá. Tag `[s155, spec-review-pre-impl, authz-widen-nobody-has-it, ignorequeryfilters-not-inverted, order-set-rule-underfit]` - **[verbatim → git 8b6df0a closeout] S146 (07-22) PRE-COMMIT spec-v2-applied (governance 20 file) — 2 MAJOR THẬT (cả hai của LEAD); nấc `verified` tự-chạy-lệnh không-tin-lead:** F1 `session-end.md` còn `hook-3-path` GẠCH-NỐI dù worker CE đã chỉ đích-danh (class "residual có người chỉ tận nơi vẫn rớt") + bất-đối-xứng nội-bộ (`pause.md` đã 4-path). F2 phép quét cardinality của lead siết LỆCH-TRỤC (co-occurrence CÙNG-DÒNG + 1 mẫu-chữ) → re-run HEAD tiền-vá lọt 4 ca thật gồm chính F1. F3 HELD (git show da7ee8a: hook 4-path + `-File` re-đọc mỗi Stop). 🔴 Bài rút: lead sửa 1 phép quét 4 lần/phiên vì mã-hoá ý-định NGỮ-NGHĨA vào regex; nấc đúng = lưới-soát-cho-người + allowlist CÓ TÊN + use⟂mention; lần-4 = citation-trap (dò bắt chính nốt-vá vì nó trích giá-trị cũ). - **S147 (07-23) DIAGNOSIS-review PE attach TraLai (no diff — verify root-cause + stress fix) — Diagnosis PASS 5/5, fix CORE-safe/EXT-unsafe:** 5 claims verified from disk; BE-no-guard CONFIRMED **intentional** by S78 changelog L9 ("handler KHÔNG guard drafter-only → approver upload no-403") + sole pipeline behavior=ValidationBehavior. 🔴 **MAJOR blind-spot:** `attachEditable=isDrafter&&isEditablePhase` SAFE for GeneralAttachmentsSection (:2013 readOnly=raw, no carve-out) but UNSAFE for SupplierAttachmentsCell (:2758) whose readOnly=**itemsReadOnly** (`readOnly&&!approverEditMode`, Mig28-F3 ChoDuyet approver-edit) → naive REPLACE breaks approver QuoteDocument edit in ChoDuyet; SAME gap in optional BE guard (carve-out {ChoDuyet+ApprovalAttachment} misses ChoDuyet+QuoteDocument). **Scope trap:** isDrafter@:140 in MAIN scope, OUT-of-scope at :2013/:2758 (child comps take only {ev,readOnly}); changing :421 over-broadly hits HoSoLinkRow:2017. **Completeness:** WORKSPACE (readOnly=false, picker editableOnly∋TraLai) already edits comparison-doc in TraLai → bug is LIST-detail-only (:574/:669 hardcode). LESSON: **decouple a gate → trace if shared prop already carries a carve-out (itemsReadOnly ≠ raw readOnly); "same fix" for sibling surface may hit a DIFFERENT gate source.** ## S152 (2026-07-26) — D2 Fidelity-gate 6 gist "CỤM BỔ SUNG" (coverage-diff) — **PASS_WITH_FIXES** (A/B/C/D PASS · E FAIL) - **Census thay spot:** 307/307 trích có trong verbatim CẶP (275 exact + 32 sau khi hoàn `'`→`"`), 307/307 chứa ĐÚNG token gắn nhãn, 307/307 token thật-sự VẮNG khỏi gist tiền-append (0 gap thổi-phồng). `ref`=46 khớp đúng claim lead. Trích = cửa-sổ ~150 ký-tự cố-định, token ở ~27% → cắt giữa từ ở 2 biên nhưng payload (file:line/finding) còn nguyên ⇒ điều-hướng được, KHÔNG rác. - 🔴 **E FAIL — class-gap hệ-thống, chữ-ký sạch:** máy-trích emit file-ref CHỈ cho `{.cs 101/.tsx 45/.ts 16/.ps1 8}` = 170 token, **ZERO cho `{.yml,.json,.slnx,.csproj,.sql,.config}`** ⇒ 13 token infra vắng ở 5/6 cặp. Nặng nhất: `deploy.yml` (chính file pipeline, trong gist của vai CI/CD!) · `appsettings.Production.json` (16 lần trong verbatim) · 2× `s59-*.sql` (chạy TAY prod ngoài pipeline) · `memory-budget.json` (single-source canonical CLAUDE.md). Header cụm TỰ đặt chuẩn "file-ref phải sống trong gist" mà KHÔNG khai N/A ⇒ trượt bằng chính thước mình. - 🔴 **3 THƯỚC-HỎNG (bug ở phép đo, không ở vật):** (1) md5 disk vs `git show` — spec gate ghi vậy — báo FAIL GIẢ 3/6 verbatim do worktree CRLF ⟂ blob LF (autocrlf=true + 188 file legacy `i/lf w/crlf`); đúng phải `git diff HEAD --quiet` hoặc strip-CR 2 phía. (2) `grep -c distill-gen` vô-dụng vì CHÍNH header cụm chứa chữ "distill-gen giữ" (citation-trap nhẹ) → phải so VALUE `distill-gen:\s*\d+`. (3) `grep -iF` trên MSYS trả **0-hit im-lặng** cho pattern ASCII trong file UTF-8 (`Mig42`: `-F`=1 nhưng `-iF`=0) = bẫy vắng-mặt-trông-giống-sạch S146 — thoát nhờ đối-chiếu Python. - **Tự bắt 2 lỗi của CHÍNH mình trước khi báo:** "Mig 47/50/42/46 MISS" = artifact chuẩn-hoá của tao (`Mig42` liền không dấu cách, có ĐỦ 2 phía) · context-regex `.{70}` trả RỖNG đọc nhầm thành sạch → phải `.{0,70}`. ⇒ **LUẬT: mọi MISS phải literal-grep XÁC-NHẬN 2 phía bằng công-cụ THỨ HAI trước khi vào report.** - D re-ground từ đĩa: `docs/gotchas.md` count=83/max=83 ⇒ 0 nhãn `gotcha #N>83`; soi NGƯỢC 24 dòng gotcha ≤83 tìm mirror-error (run-number đội lốt gotcha) → 0 ca, mọi #N đều là gotcha thật trong ngữ-cảnh nguồn. Tag `[s152, d2-fidelity-gate, coverage-diff, extractor-ext-blindspot, thuoc-hong-x3]` --- ## @S159-curate — moved from L1 (S155-đợt2 verbatim, moved-not-cut) - **S155-đợt2 (07-27) PE delete-approver DIFF-review #2 (12 FLAG 2H/4M/6L · ĐỪNG-DEPLOY):** 🔴 class MỚI **`hợp-đồng-đứt-giữa-2-bờ`** — FE type chép tay khai `allowApproverDelete: boolean`, BE record chỉ 8-member KHÔNG có cờ ⇒ nút CHẾT mà `tsc` + `dotnet build` + 561-test đều XANH (mọi thước đo đo chỗ khác) ⇒ **phép rẻ nhất = đếm member DTO vs khoá FE + `grep -c ` ở file dựng DTO**. · policy-gate `X.Delete` chặn ĐÚNG nhóm cần dùng (đo DB: 11/13 vai `CanDelete=0`, 2 seeder KHÔNG BAO GIỜ nâng) ⇒ owner gỡ policy; **verify "gỡ authz" = truy TỪNG dòng chặn thành bảng + grep `.First()` fallback + grep `Admin` trong chính file** (gỡ policy sinh LOW mới: endpoint thành máy-dò 4-loại-phản-hồi cho mọi tài khoản). · **mã ĐỔI giữa lượt soi ⇒ re-đo đĩa TRƯỚC verdict**; test đổi chiều (`==X` → `==null`) = **ĐỔI-SPEC hợp lệ ≠ nới-assert** vì 2 mệnh đề loại trừ nhau (nới = mệnh đề mới SUY RA được từ cũ). · cascade `Add con → Remove cha → 1 SaveChanges`: chứng "site duy nhất" bằng liệt-kê-vét-cạn 34 `Remove` → lọc 8 → xét cha-con từng cái. Tag `[s155-dot2, hop-dong-dut-2-bo, policy-gate-do-DB, re-do-dia-truoc-verdict]` ## Moved @S160 (2026-07-29) — verbatim from L1 (moved-not-cut) ## S149 (2026-07-24) — gate hội-tụ-bookend [LEAD GHI ON-BEHALF @S150 — M9/B3 theo H2-F4 (1 invocation thật → 0 entry); nguồn: `runs/2026-07-24-S149-hoi-tu-bookend/sub-reviewer-hoi-tu.md` 15.733B] - `/fable-real reviewer` gate spec hội-tụ-bookend: **GO-WITH-FIXES 1C/6M/4m** (CLEAN 218K, 0 garble) — spec v1→v2 trước wave implement 5-lane Opus (5/5 done 946K 0-garble). Lưu ý sổ: lượt gate adap-backlog `wf_f4e4c006` KHÔNG tính invocation vai này (reviewer-lane **skeleton-ruột-rỗng** — khung 274B, 0 append, return+resume đều fail → em-main-solo re-do; xem sổ garble sub-class @S150). ## @S161-curate (2026-07-29) — moved from L1 HOT (hook-cap 24.5KB > 17.1KB) - **S159 (07-29) dashboard "toàn trình" đợt-4 FE-only (fe-user 984+/337−, PWF 7 FLAG 0H/2M/5L):** 🔴 **`tsc` XANH đo ÍT hơn vẻ ngoài** — `fe-user/tsconfig*.json` KHÔNG có `strict`/`strictNullChecks` (chỉ `noUnusedLocals`) ⇒ **tra cờ tsconfig TRƯỚC khi trích tsc làm bằng chứng**; ngược lại `noUnusedLocals`+pass = bằng chứng MẠNH HƠN grep cho claim "đã gỡ khối X" (compiler chặn nếu sót import). · class **`nhãn khẳng định chiều-ngược`**: dot-map `none='chưa tới'` — không-suy-diễn "đã xong" là đúng, nhưng "chưa tới" CŨNG là khẳng định ⇒ sai cho GĐ ĐỨNG TRƯỚC + sai khi `contractId != null` **có sẵn trong payload**. · pager tính `data.page±1` (keepPreviousData ⇒ stale) thay vì state ⇒ double-click = no-op. · **verify đích điều hướng phải đọc CẢ breakpoint trang đích** (panel `hidden lg:block` ⇒ ngõ cụt mobile; trang đích tự có nhánh `matchMedia` mà caller mới không copy). · regression đo HEAD⟂work bằng `grep -c` từng token: count 5→2 mà KHÔNG mất nhãn (inline-prop → `STAGES[i].title`) ⇒ **đếm lệch phải truy CẤU TRÚC trước khi kêu hồi quy**. · tự tính lại 4 tỉ-số contrast + tra `@theme` mọi `var(--color-*)` (0 dòng `--color-*: initial` ⇒ nấc mặc định còn) — 3/3 số designer ĐÚNG. · lời khai sub-file "766→1.130 dòng" SAI (đĩa 1.413 = 766−337+984). [→ `runs/2026-07-29-S159-tong-quan-pipeline-menu/sub-reviewer-diff-dot4.md` 28,5KB] - **S159 (07-29) đợt-5 menu 6-leaf HĐ + endpoint `/contracts/deleted` (PWF 10 FLAG 0H/4M/6L):** 🔴 **con-số TRONG CHÚ THÍCH cũng là khẳng-định đo-được** — diff SỬA comment D3 thành "NAY CÓ 2 chỗ `IgnoreQueryFilters`", `grep -rn` ra **3 file/17 site** (ApprovalWorkflowV2AdminFeatures 15 site); tôi suýt duyệt bằng mắt ⇒ **luật: comment mang số ⇒ chạy phép đếm, và số viết dưới dạng LUẬT ("chỗ duy nhất ⇒ CẤM…") sai thì lan sang người sửa sau**. · class **`mirror-nửa-vời khai thừa phạm-vi`**: comment nói "Hộp thư + Tổng quan viết HOA" nhưng "Hộp thư" render bằng `StaticLeaf` KHÁC component ⇒ đọc comment ≠ đọc call-site. · **cookie-cutter phải soi CẢ phần PE đã CHẶN**: bản HĐ copy list-deleted nhưng bỏ `disabled={deletedView}` ⇒ click row → detail 404 → panel **trắng** (page thiếu nhánh `isError`) + mobile navigate ra trang 404. · mirror 2-app: fe-admin ẩn `Ct_*` (⇒ 21 leaf mới KHÔNG cần route) nhưng `Khkk_*` KHÔNG ẩn ⇒ thiếu 2 staticMap = drop silent #50 — **kiểm hide-filter TRƯỚC khi kêu thiếu mirror**. · `tsc -p tsconfig.app.json` EXIT=0 + `noUnusedLocals` = chứng cắt-hero-không-mồ-côi MẠNH HƠN grep (nhắc lại: fe-user KHÔNG bật `strict`). · `Contracts` ∈ `MenuKeys.All` ⇒ policy `Contracts.Read` có thật; `MenuPermissionHandler` khớp ĐÚNG-KHOÁ, KHÔNG kế thừa root (#82). [→ `runs/2026-07-29-S159-tong-quan-pipeline-menu/sub-reviewer-diff-dot5.md`] - **S160 (07-29) reviewer CHỐT-CUỐI /fable-real (verify 13-fix landed) — #53 chết sau Trục-1+Trục-2, đĩa cứu:** khuôn review-của-review: chấm "fix ĐÃ LAND + ĐÚNG codebase, không đẻ lỗi mới" — **12/13 landed-đúng + ~30 anchor re-verify THẬT @HEAD, 1 half-fix**. Bài: (1) **fix áp NỬA spec = dư-lượng thật** — W7 §② sửa badge-nguồn nhưng bảng §① cùng file sót ⇒ soi CẢ FILE khi nhận "đã fix", không chỉ chỗ được trỏ (lớp vá-1-nửa-cùng-lớp S122); (2) **anchor-label ⟂ thân** — gate-5-anchor W3 vẫn liệt `PEWS:1008` sau khi thân phán khuôn đó SAI ⇒ anchor-list là artifact riêng phải sync khi thân đổi; (3) **anchor off-by-N** — "2 checkbox :1267-1268" trúng 1 (SkipToFinal ở :1256) ⇒ dải anchor phải grep CẢ 2 symbol; (4) **verify NGƯỢC premise clone**: re-đo `ContractWorkflowService.cs:191-198` admin-override-gán-qua-biến + `ContractChangelogConfiguration:22-25` FK-Cascade + `ContractAttachmentFeatures:56-152` 0-IDOR — 3/3 premise HIGH clone ĐỨNG ⇒ clone-review có răng thật; (5) **O-A moot-check**: owner để-mở ⇒ F-C3/F-C5/F-S2-grant MOOT-đúng (không siết thì không grant), KHÔNG phải lead né. #53 lần 2/phiên trên reviewer — return "Trục-2: xác vị file…" (mẩu giữa việc) nhưng sub-file 8KB có Trục-1+Trục-2 đủ ⇒ **lead finalize VERDICT+LỖI-MỚI+LEFTOVER on-behalf từ đĩa** (0 mất kết-luận vì ghi-đĩa-trong-lúc-làm). Tag `[s160, chot-cuoi-verify-fix-landed, half-fix-soi-ca-file, anchor-label-vs-than, verify-nguoc-premise-clone, o-a-moot-check, 53-doc-cuu]` - **S160 (07-29) review SPEC-BỘ dry-run KHKK→HĐ-cứng [engine `/fable-clone` 6 lane opus + `/fable-real` chốt fable; `runs/2026-07-29-S160-khkk-dryrun-plan/review-synthesis-clone-s160.md`]:** 6 lane (anchor-A rỗng #StructuredOutput-fail nhưng ghi-đĩa-lượt-1-2 cứu · B/C/wave-logic/owner-consist/security). **5/5 verdict SUA-TRUOC-THI-CONG, hội tụ cao** ⇒ lead-verify 5 claim load-bearing 5/5 CONFIRMED đĩa. Bài đắt: (1) **review SPEC ≠ review CODE — bắt lỗ ở acceptance + default-lấn-quyền + hố-chưa-khai, KHÔNG chỉ anchor** (anchor 24-28/28 đúng dòng nhưng spec vẫn hỏng cấu-trúc); (2) **seeder-grant no-op = 403 giết-feature IM LẶNG** — row Permission đã tồn tại CanRead-only ⇒ grant kiểu insert rơi skip-existing `continue` (`DbInitializer.cs:2242-2245`), phải UPGRADE-if-exists (`SeedProcurementMasterAccessAsync:2367-2374`); **acceptance đếm ROW = 0-bit, phải đo CỜ CanCreate/CanUpdate**; (3) **owner-authority finding** — lane owner-consistency bắt lead đặt default lấn đúng chỗ owner phán "để yên" (O-3 "hợp đồng cứ từ từ" + STATUS:13 tái-khẳng-định) ⇒ surface AskUser thay vì tự quyết → anh chọn O-A gỡ hẳn wave; (4) **"204 KHÔNG 409" PASS SẴN** = acceptance 0-bit nửa-vế vì nhánh trình không đọc workflow (`ContractWorkflowService.cs:70-89`) — vế răng = `currentApprovalLevelOrder=1` phải chạy tới lượt DUYỆT; (5) **FK-547 compiler-không-chặn**: gọi `LogWorkflowTransitionAsync(Guid contractId)` với plan.Id = enum/Guid cast được nên build xanh, nổ runtime — dùng bảng changelog RIÊNG của module mới; (6) **choke-point "DUY NHẤT" sai** — admin-override gán Phase QUA BIẾN (`:190-193`) nên literal-grep miss (lớp #81), phải kê 2 write-path. **anchor-B census tên-test: repo 0/460 tên thuần-Việt ⇒ khuôn = English-predicate** (owner chốt đổi). Ensemble ĐÓNG GÓI C2 ăn: 6 lane ≤3-file + khung-rỗng-lượt-1-2 ⇒ 0 lane chết dù 1M+ token. Tag `[s160, review-spec-bo, seeder-grant-no-op-403, acceptance-dem-row-0bit, owner-authority-surface, 204-khong-409-pass-san, fk-547-compiler-mien, choke-point-2-write-path, test-name-census-repo]` ## @S162-curate (2026-07-30) — moved verbatim từ L1 (hook 23.9KB > sàn 17.1KB) - **S161-W2 (07-29) KHKK CRUD review — PWF 12 FLAG 3C/5M/4m `[chết #53 sau Trục-4 (13.9KB ghi-từng-trục sống trọn) → lead đo Trục 5-7 + verdict on-behalf; 11 FIXED cùng lượt + 1 GIỮ]`:** 🔴 **Trục-1 hợp-đồng FE↔BE VỠ 6 điểm khi 2 lane viết SONG SONG từ cùng spec** — tsc+build+574-test đều XANH cả 6: route picker lệch tên (F-1, 404 đội lốt empty-state vì TanStack nuốt lỗi + `?? []`) · body `purchaseEvaluationId` vs `PeId` (F-2 — **D1 của BE lập luận "FE đọc cùng spec sẽ khớp" = GIẢ ĐỊNH, không phải phép đo; FE đã KHÔNG làm thế**) · dossier body thiếu planId (F-3) · FE chỉ gọi POST khi BE ép Id=null ⇒ Sửa-đẻ-bản-sao im lặng (F-4) · `peTenGoiThau` (F-5) · `winnerSupplierNames` BE không có (F-6 — **bị F-1 CHE: mảng rỗng nên .map chưa chạy, vá F-1 xong mới lòi** = 2-lỗi-che-nhau). **Luật rút: đối chiếu hợp-đồng = so ROUTE+FIELD từng cái giữa types-FE và record-BE trên ĐĨA, đừng tin lời khai lane nào.** · F-8/F-9 security: **list bịt mà detail/download 0-rào ⇒ rào list chỉ còn là UX** — đối chứng twin PE :877-899 CÓ guard + S89 nháp-riêng-tư ⇒ thụt chuẩn, không phải "khuôn vốn thế" · F-12 INNER-join Projects (global-filter) = picker silent-vanish — lớp "vắng-mặt trông giống ổn". Trục-4 picker-khớp-rào ĐẠT (3/3 rào PE mirror đủ). Tag `[s161-w2, hop-dong-2-lane-song-song-6-diem-dut, loi-khai-la-gia-dinh, 2-loi-che-nhau, list-bit-detail-mo-rao-thanh-ux, inner-join-global-filter-vanish]` - **S161 (07-29) W1 KHKK tiền-commit (Mig 69 + seeder + Designer type-10) — PWF 10 FLAG 1H/3M/4m/2L:** 🔴 **HIGH lại nằm ở `git` chứ không ở mã (S155 tái diễn):** 2/3 file Mig 69 UNTRACKED `??` mà snapshot đã tracked-M ⇒ `commit -a` nạp model 7 bảng nhưng BỎ migration; build+566 test vẫn xanh ⇒ **gate = `git status --porcelain -- src tests | grep '^??'` phải RỖNG ngay trước commit**. · **MAJOR bắt được nhờ đi NGƯỢC lời-khai FE:** comment FE tự khai "nhãn lấy từ BE `applicableTypeLabel`" ⇒ đi kiểm bờ BE: `AwLabels.Type` chỉ 3 entry, `GetValueOrDefault(type, type.ToString())` ⇒ UI hiện **"ContractSigningPlan"** tiếng Anh và `useState(\`Quy trình ${label}\`)` **GHI chuỗi Anh vào cột Name DB** — lớp *hợp-đồng-đứt-2-bờ*, tsc+build+test đều xanh. **Luật rút: câu comment dạng "bên kia lo" = ĐI ĐỌC BÊN KIA.** · seeder 5/5 PASS (call sau revoke `:2109`>`:2096`; revoker chỉ `Hrm|Off|Personal` ⇒ không lật 2-chiều; `TryGetValue` tuple `(RoleId,MenuKey)` — khuôn 1-role sẽ ném dup-key, unique-index `PermissionConfiguration:26` cứu) nhưng **acceptance "đo CỜ" chưa đo được ở đâu**: Dev DB **0 row** `Khkk*` cả MenuItems lẫn Permissions (menus 100 vs prod 142) ⇒ chưa nhánh nào từng chạy. · **`grep`-cùng-lớp bằng TOKEN-SONG-SINH** (`VehicleBookingLevelOpinions` repo-wide) mạnh hơn grep tên-mới: chứng 3/3 site đủ + 0 site thứ 4. · 2 chú thích cùng file nay SAI SỐ ("7 bảng"/"7 khối" → 8) + comment nguồn `MenuKeys.cs:37` "CỐ Ý NGOÀI All" nay sai + anchor `(:614)` trỏ dòng TRƯỚC-commit (đúng = :645) ⇒ **diff sửa mã phải sửa MỌI số/neo trong chú thích cùng file**. · STATUS.md `Menu keys 54`/`Policies 216` không đổi dù |All|=55 ⇒ derived-drift. Tag `[s161, high-o-git-khong-o-ma, hop-dong-dut-2-bo-nhan-BE, token-song-sinh-sweep, seeder-upgrade-if-exists, comment-mang-so-va-neo]` --- ## @S165-curate (2026-07-31) — moved verbatim từ L1 (hook 22.6KB > sàn 17.1KB) - **S164 (07-31) gate K1 danh mục SP-002 (`ContractCatalogEntries`, Mig 70) — PASS-WITH-FLAGS 9 finding/0 blocker kỹ-thuật:** build 0W/0E + **597 test** (45D+552I) tươi. Lane khai ĐÚNG 100% ở chỗ đo được: seed **86/86** parse-máy khớp transcribe từng dòng (chỉ 8 mismatch = đúng tập lane đã khai), phân bố 5/10/5/23/14/15/13/1, SHA-pair FE `d71a9e3b…` ×2 khớp claim. **Bài thu:** ① 🔴 giá-trị lớn nhất KHÔNG nằm ở mã mà ở **GATE QUY-TRÌNH**: spec đặt PRE-gate owner (`OG-6`) + kế hoạch **tách 2 commit** (code trước, seed sau khi gật) — code đúng hết mà commit gộp là **vượt quyền owner**; seeder per-Code idempotent KHÔNG có nhánh update ⇒ gật muộn = phải UPDATE tay. ② **2 quyết-định hợp-lệ ghép lại đẻ ghost-wire**: lead bắt key vào `MenuKeys.All` (để có menu row) + spec bắt controller mirror khuôn `Roles="Admin"` ⇒ 4 policy `ContractCatalog.*` sinh ra mà **0 endpoint tiêu thụ**; ma trận CRUD chỉ điều-khiển HIỂN-THỊ, tick CanCreate vẫn 403 / bỏ tick CanRead vẫn GET được (lớp #82) — **phải đo `grep policy` chứ đừng suy từ "key đã vào All"**. ③ **default-lấn-ngữ-nghĩa**: spec `IncludeInactive?` (mặc-định-LOẠI) → code `IsActive?` (mặc-định-GỒM) ⇒ cột "ẩn khỏi picker" chỉ ẩn nếu MỌI consumer nhớ truyền tham số. ④ drift DELTA đo được (All=56, policy=224) mà `STATUS.md:6` chưa đổi ⇒ acceptance "khai cùng commit" chưa đóng. Tag `[s164, gate-quy-trinh-owner, ghost-policy-2-quyet-dinh-hop-le, default-lan-ngu-nghia, seed-doc-may]` **Evidence:** `.claude/workflows/runs/2026-07-31-S164-4gd-khkk-fanout/sub-reviewer-gate-k1.md`. ⚠️ Sổ này **18.8KB > 17.1KB** — nợ curate lượt sau. - **S162 (07-30) cây 4-folder GĐ (FE-only 2 app) — PASS-WITH-FLAGS 8 flag/0 blocker:** 🔴 class **`im-lặng-về-độ-chính-xác-của-con-số`** — 3 ca cùng lớp 1 diff, tsc+build ×2 xanh: hook VỨT `total` khi `pageSize:200` ⇒ không biết mình bị cắt, badge tụt không dấu vết · `pe.ContractId = contracts[0].Id` ⇒ phiếu liên-danh N HĐ chỉ nối 1 mà badge in như thật (**tái phát cardinality S87/S88 — field làm KHOÁ-NỐI phải đi đọc WRITE-SITE của nó**) · fallback `?? '(chưa cấp mã)'` trộn 2 nguyên nhân ⇒ **khẳng định SAI**, không phải degrade. · **#82 ngược chiều:** FE gate OR nhiều menu-key nhưng `MenuPermissionHandler.cs:40` khớp CHÍNH XÁC 1 key ⇒ OR làm gate LỎNG HƠN policy, tự chuốc 403; **gate query = ĐÚNG key policy của endpoint**. 2 endpoint cùng diff kết luận NGƯỢC nhau (`/contracts` `[Authorize]` trần ⇒ KHÔNG 403) ⇒ đo TỪNG cái. · **Nhãn ✓ không có phép đo:** rubric 'responsive ✓' mà harness grep 'grid-cols-[19rem'=0 hit ⇒ 2 trang lưới chưa từng render; **đọc `^import` của harness = cách rẻ nhất biết ảnh CHỨNG được gì**. Tag `[s162, im-lang-do-chinh-xac, total-bi-vut, contracts0-cardinality, or-key-long-hon-policy, nhan-tick-khong-phep-do]` **Evidence:** `.claude/workflows/runs/2026-07-30-S162-cay-4-folder-gd/sub-reviewer-1.md` · lead áp 5/8 flag (F-1/3/4/6/7) + F-8 sửa memory designer TRƯỚC ship `bfc7b79`; F-2 (liên-danh N-HĐ) + F-5 (layout 19rem chưa render thật) = giới-hạn khai thẳng lên HANDOFF slot (56). ## S159 (2026-07-29) — review diff tổng-quan pipeline (đợt-1, run tong-quan-pipeline-menu) [LEAD SEED ON-BEHALF @S164 — H2 P2 @S163; run bị owner chốt "bỏ mạch" @S163 nhưng lane review ĐÃ chạy thật, distill giữ bài] - {nấc: verified (lead đọc lại sub-file 16.761B) · evidence: `runs/2026-07-29-S159-tong-quan-pipeline-menu/sub-reviewer-diff-tongquan.md`} - **7 FLAG (2M+5L), 4 bài giữ:** ① [M] a11y AA — 2-3 `