Files
solution-erp/.claude/agent-memory/reviewer/archive/2026-07.md
2026-08-01 09:00:14 +07:00

96 KiB
Raw Blame History

Reviewer Agent — Archive 2026-07 (L2 verbatim, FROZEN additive-only)

Recovered S102 (2026-07-06): 5 entry verbatim (S97 · S97-bis · S98×3) bị cut-not-moved tại commit f229b07 (S101 nén L1, digest claim "Detail → archive/2026-06.md" nhưng verbatim chưa từng được move — H2 harvest-curator Fidelity-FLAG S102). Trích content-exact từ git show 5ee32c0:.claude/agent-memory/reviewer/MEMORY.md (PS .NET per-line match, line-ending normalize LF, 0 ký tự mất). Thứ tự giữ nguyên như L1 gốc (newest-first: S98×3 → S97-bis → S97). Quy tắc file: NEVER rewrite existing bytes; entry mới APPEND cuối file. Map: archive/_INDEX.md.

  • S98 (2026-07-02) FIDELITY GATE gist impl-frontend 2026-H1 (10 record → 6 cụm + 5 reflection) — PASS-với-sửa (1 minor): 34/34 substring-pointer count==1 (grep -o -F đếm occurrence, gồm cặp bẫy "gotcha #50"≠"gotcha#50" resolve 2 record khác nhau đều hợp-cảnh). 3 interpretive-flag verify GROUND-TRUTH ngoài verbatim: double-rAF (code ListPage:270 comment "2 rAF để browser commit translate-x-full TRƯỚC" + duration-200) · 2 PageHeader song-song (4 file disk thật ×2 app) · wildcard ev.*Note theo-từng-mut (đúng 3 call-site 1770/1785/1841). FLAG cwd-misland hướng-chéo: session-log S76:40 CORROBORATE verbatim (cd fe-admin → rơi fe-user/.claude) + .gitignore L109-111 comment trung-tính → draft trung-tính ĐÚNG, không sửa hướng. Sửa duy nhất: R4 parenthetical nói chuỗi "nằm trong chính gist" — misleading, chuỗi resolve count==1 trong archive. Lesson: fidelity-gate 3 lớp = so-verbatim + pointer-arithmetic + ground-truth-code cho MỌI chỗ gist DIỄN GIẢI vượt verbatim; honest-empty BẤT-NGỜ="không" > bịa filler; verbatim TỰ mâu-thuẫn (S52-vs-S53) → gist flag discrepancy chứ KHÔNG resolve bịa (anti-S88-fabrication-by-merge, lần này draft làm đúng).
  • S98 (2026-07-02) VERIFY LANE V3 cicd-monitor L1-curate moved-not-cut — PASS (0 blocking, 3 minor): sha256 line-level backup-L73/74 == archive-L7/8 (2398/1909B text) + byte-arithmetic đóng EXACT (removed 4309 raw stubs 1451 = 2858 = size-delta 19917→17059) + diff duy-nhất 73,74c73,74 + CR/LF profile 86/86→86/86 không đổi + FROZEN archives 0-diff + _INDEX 78=2+39+20+6+7+3+1 pointer-resolve count==1. Tool-lesson Windows byte-verify: MSYS grep/sed/awk = TEXT-MODE strip \r (grep -c \r báo 0 trên file CRLF thuần!); od-token-pipeline đếm sai (641 vs 86 — token-split artifact); ground-truth = .NET ReadAllBytes / wc -c / tr pipe / od -c tail. Moved entries CRLF→LF normalize (encoding-only, 0 ký tự mất — Write tool ghi file mới LF uniform). Minor caught: MEMORY.md "Last curate" ledger vẫn S80 (S98 chưa ghi sổ, discoverable qua stub "(curate S98)"); archive-header chữ "byte-exact" đúng trừ CR-terminator.
  • S98 (2026-07-02) VERIFY LANE V1 re-tier mega-line STATUS/HANDOFF conservation (uncommitted) — PASS (0 mismatch): blurb S94+S93 cắt khỏi mega-line = VERBATIM trong archive tier-S98 (STATUS IndexOf ordinal 9412/11090 · HANDOFF 6147/7775; HEAD cross-check cùng blurb, HANDOFF lệch +51 = đúng bundle-hash morning-edit TRƯỚC blurb). Proof-of-no-other-deletion = arithmetic full-accounting prefix+b94+sep(·,3)+b93+tail(125=old-pointer) == lineLen exact ×2 file — mạnh hơn spot-check. Old-pointer tái hiện trong pointer mới (archive-S98 + archive-S94 đều =1). Kỹ thuật-bẫy: commonPrefix lấn 1-char (* đầu **Prev trùng * mở italic pointer mới) → Replace-decompose trên removed-region FAIL giả; fix = IndexOf(blurb) trên FULL line. Line-count bằng (92/92, 12/12) → index-by-index diff enumerate đủ 6+2 dòng vào allowed-list. Flagged: archive ?? UNTRACKED — phải git add cùng commit kẻo pointer gãy. Read-tool truncate dòng >2K = KHÔNG verify được mega-line → PS ReadAllLines UTF8 + ordinal IndexOf là đường duy nhất.
  • S97-bis (2026-07-01) PE EndsBeforeCeo CONFIG→RUNTIME + Mig 60 backfill (bug anh Kiệt FDC, cross-stack+mig, live UAT) — PASS (0 issue): field EndedByLevelFinalize set true DUY NHẤT nhánh level-finalize service:871 (grep-all confirm 5 nhánh DaDuyet: 671 drafter-auto / 873 finalize-SET / 911 ccm-delegation / 943 all-steps-CEO / 1049 V1-legacy — chỉ 873 set, 4 nhánh còn lại giữ false = đúng semantics). 4 projection nhất quán: detail ternary phase==DaDuyet?field:true (:1153) · List/Inbox Phase==DaDuyet?field:config-subquery (:647/:767) · ListApproved direct field (filter DaDuyet :176). Migration 3-file OK (Designer+Snapshot có bit-NOT-NULL-default-false); backfill marker LIKE N'%Duyệt KẾT THÚC tại%' KHỚP-EXACT service comment:883 (system prefix, user-comment nối SAU) + table PurchaseEvaluationApprovals verified (config:148+DbSet) + Phase=7=DaDuyet verified enum. ccm-delegation comment [CCM duyệt done miễn CEO] KHÔNG match backfill → false nhất-quán runtime. EF-translate ternary List/Inbox CONFIRMED runtime (không giả định): PeDraftVisibilityTests gọi ListPurchaseEvaluationsQuery full-projection nằm trong 395 Infra PASS. FE 2-app SHA256-IDENTICAL b7abbc2f, gate finalizeFlowStep=endsBeforeCeo?find:null + banner:278 + type endsBeforeCeo:boolean có sẵn 2 DTO. Build slnx 0w/0e + 440 test (45D+395I) 0-fail + tsc×2 exit-0 (self-verified, không tin claim). Test repro peFinButWentCeo (cùng-config finalize + field=false → EndsBeforeCeo=FALSE) = contrast quyết-định runtime-vs-config, xuất sắc. Anti-pattern-none: 11-file đúng-scope 0-drift, extend-in-place test NET+0-method giữ 440. Lesson: backfill LIKE-2-wildcard trên chuỗi VN-đặc-thù = false-positive risk MINOR-lý-thuyết (chỉ phiếu DaDuyet-hiện-tại 1-lần, UAT ít-phiếu) KHÔNG đủ FAIL. Config→runtime split đúng: chỉ THÊM chính-xác cho DaDuyet, non-DaDuyet giữ heads-up config như trước = không regression. Re-affirmed @S97 Part-5 session-review lane (spawn fail-return-schema → verdict recovered từ chính entry này per #53-recover-from-diary; em-main grep bổ-sung: 0 wrong-table pattern nào khác ngoài Mig 60 — đã fix Mig 61). (addendum on-behalf H2-proposed @S98)
  • S97 (2026-07-01) PE finalize UAT ×2 app: reword badge + đảo default checkbox opt-out→opt-in (uncommitted, prod-live anh Kiệt FDC) — PASS (0 issue): 4 hunk/file × 2 = 8 total, 12ins/12del, no thừa. E1 useState(true→false) L57 · E2 reset setApplyLevelFinalize(false) L221 · E3 helper-text reword (strings KHỚP spec verbatim) · E4 badge không trình tớiKết thúc tại {finalizeLevelName ?? finalizeStepName ?? 'cấp trên'} + template-literal title. SHA256 full-file IDENTICAL bcf812fd… ×2 + git-diff --no-index exit-0. Comment L121 không trình tới INTACT (bare-string 2-site: comment giữ + JSX đổi) + e.target.checked handler L664 INTACT (spec correctly NOT flip). Logic-non-break VERIFIED: default-false → eligible-untick → sendPrice(L171)=false + shouldPickPrice(L496)=false → price-picker KHÔNG bắt (spec pt6 ✓); payload L200 (approverFinalizeEligible ? applyLevelFinalize : true) = pre-existing S96 opt-out no-op cho non-eligible, unaffected by flip. Type finalizeStepName/LevelName: string|null (purchaseEvaluation.ts:149-150) → ??-chain TS-safe. 0 BE/test/mig leak. Build fresh ~17:55 ×2 (fe-user hash DxUomy4C KHỚP impl-claim; fe-admin rotate DkyQ0xCd→disk l_kwCZIF = #69 normal). Anti-pattern-none: precedent-backed cosmetic+default-flip, byte-mirror tight.
  • S101 H18 WF2 governance re-run (self=workflow-lane · em-main synthesized): re-verified S100 Harness-18 adopt (5ee32c0, governance-only) — original WF2 wf_31ea3985-92c lost to CLI-restart → fresh wf_955643c3-f7d PASS_WITH_CONCERNS. Lane-A detector-teeth PASS (fault-inject 4/4 -RepoRoot temp-tree — proved detector FLAGS injected-stale, not happy-path). Lane-B caught 1 CONCERN em-main missed in S100 sweep: workflows/README.md:51 stale label "ledger orphan-scan" (NO _ledger token → grep-exact sweep skipped) → FIXED S101. Lesson: exact-token sweep misses paraphrased labels — widen to concept-phrase when retiring a named artifact. Lane-C #53 return-garble (workflow-lane returned no StructuredOutput) → recovered first-hand, NOT re-spawned (feedback_agent_return_garble_recover).
  • S101 H19 WF2 review LANE-C (adap-reports + honesty · self=reviewer · wf_5f308fd8-744=WF1): PASS. 4 adap-reports (H19 fable-clone + 3 model-tier) + send-email 6c. Hashes recompute indep MATCH (H19 6909299a + model-tier ee00d253/a7ff304b/eed277f7), all carry reviewer_gate: PASS. 12/12 honest; Q2 hysteresis 0.85/5/2 verbatim budget.json:35-37. Danger-phrase "verified" only in G-011 legend + "verified-pending-restart"; nấc="designed+will-dogfood, thật-mode CHƯA chạy". Lesson: hex→SHA disambiguation — recompute BOTH strip/no-strip variants to prove a hex string is a content_sha256 BODY-hash not a commit-SHA (line-29 5f511fe5→5f8b8504 = hash-transition, git cat-file=not-commits, claim TRUE presentation-nit only).
  • S101 H19 fable-clone WF2 Lane-A (toggle mechanism) — PASS_WITH_CONCERNS (1 CONCERN, 0 BLOCKING): 3 Lane-A asks all CONFIRMED — (Q1) /fable-real=Write · /fable-clone=Remove-Item mirror ultra-on/off, both carry no-hot-reload warning; (Q2) semantic INVERSE (marker-absent=ảo-DEFAULT · present=thật) consistent across 8 statements + git check-ignore .claude/fable-real-mode.on=IGNORED (line 92 AFTER !.claude/** neg line 83, verified check-ignore -v) + tracked cmd-file NOT-ignored; (Q3) GAP-1 scope-guard "N lane CÙNG 1 vai, KHÔNG mixed-roster" pinned in BOTH cmd-files + §K.C, and hmw.js VALID_ROLES independently confirmed = all 9 roles no 2-position gate (resolveModel unrestricted) → GAP-1 leak framing ACCURATE not fabricated. CONCERN (refutation that landed): marker is a WRITE-ONLY dead artifact — /fable-real.md:10 claims "Mode persist qua marker → SỐNG qua session/compact" but NOTHING reads fable-real-mode.on; /session-start BƯỚC 0.5 reads only hmw-mode.on and was NOT extended (session-start.md unmodified in git status, empty grep for any reader). Write half-loop exists, read→report→route half-loop absent → wording overstates mechanism. Non-blocking because vacuously-met-today (all-inherit → 2 positions ALREADY top-model → 0 runtime-delta; toggle manual/owner-driven by design) — bites only when Fable returns + tiering resumes. Anti-pattern: mirror-a-toggle copies the WRITER side but silently drops the READER side — a persist-claim needs BOTH write-on-set AND read-on-session-start; verify the consumer exists, not just the producer. Vacuously-met disclosure itself was clean (§K.D + mark both say "KHÔNG overclaim runtime-delta"). (dời từ Role-baseline @S102 — H2 Placement-flag; NOTE @S102: reader BƯỚC 0.5b ĐÃ wire tại S101-cuối → CONCERN closed, marker có consumer.)
  • S100 H18 WF2 synthesis + Lane-B — SYNTHESIS reviewer 2-lane JSON→overall PASS_WITH_CONCERNS (LaneA PASS + LaneB PWC, neither BLOCKING). Re-verified indep: ledger +2/0-del revert-clean · ratio-band replaced |diff|>=10 · glob replaced 3-fixed-list · 6/6 consumers 🧊-marked · every LIVE _ledger marked (unmarked=history) · CONCERN workflows/README:51 no-token points-authoritative=non-block · KEY anti-pattern HELD (stale WF2 wf_31ea3985 NOT stamped, both placeholders await fresh run). Prior S100-bis Lane-B PASS (2 minor) folded in.
  • 2026-07-10 (S108 first-real-run H19) [engine: fable-real-single · Fable-S108] (em-main harvest B3, GAP-2/3): Task single-deep-pass adversarial 3 artifact S108 (runbook 58.7KB + adap-request + email outward — $outwardFlag=Y Cat-6). Verdict FAIL — 1 CRITICAL (email claim “đã sửa comment” khi hmw.js:31-32 chưa sửa, cat xác nhận) + 4 MAJOR (2 stale-outage-claim sót §3.5/§4.3 · clone-example thiếu tier:'opus' trái K.B/floor-2 khi Fable UP · AP-4 tự-toggle trái K.D-2 · drift-note 9-vai sai vs engine-10) + 6 minor; core JSON-shape/biến/checklist/GAP-guard SOUND (7 refutation: 5 đứng · 2 vỡ về phía artifact). Learned: doc assemble-từ-N-worker → grep stale-claim theo CLASS toàn file sau khi fix đại diện (header “đã sửa 6” ≠ sửa hết) · mọi outward-claim “đã sửa X” phải cat X trước gate. Surprise: đoạn drift-note (viết để cảnh báo drift) là chỗ duy nhất mô tả sai canonical. Em-main áp 37-fix + vá hmw.js thật → verdict-fixes closed cùng phiên. Return dòng-1 Verdict-header chuẩn, 0 garble.

S112 curate (self, 2026-07-12, hook 20.5KB) — collapsed 2026-06 digest cluster from L1 Recent-activity (verbatim below; detail already in 2026-06.md / linked area files)

  • 2026-06-29 S93 Harness-16 MFE adoption review (WF2 wf_13e3d35a 3-lane PASS 0-blocking): code-gate re-derived denom-29 + leading-verb-trap DEFEATED (NEVER commit push→0 content-word) + READ-ONLY-budget proof (1 write-op .mfe-state.json); WF1-reviewer caught BLOCKING vocab-fork (memory-fidelity H6.7≠H16 → MFE+alias-map §H). Detail → adap-report harness-16-mfe. → _INDEX.
  • S92 (2026-06-29) Adversarial PROD-security hide 5 menu-groups admin-only on eoffice (uncommitted) — PASS (0 blocking, 1 awareness note): A-E all upheld; CatalogManager Danh-mục access stripped (intended-by-spec, role assigned to 0 users post-S89, flag em-main only). Detail + per-attack file:line → project_s92_admin_only_modules_revoke.md.
  • S91 (2026-06-25) PE D2 create-contract 1→N multi-winner + winner-names (FROZEN, NOT-deployed) — PASS: fix for S89-bis dead-end; codegen mid-loop SaveChanges flushes ONLY seq-row (contract built LOCAL); GiaTri per-winner Quote-sum join PES.Id; positional DTO arg-order verified 3 sites; FE mirror byte-identical; 419 PASS. Detail → archive/2026-06.md.
  • S90 (2026-06-25) PE stability-fix batch D1 (5 chg+11 test, FROZEN) — PASS: Block B re-key SelectedSupplierId→IsWinner (single unchanged proven); CEO-notify SaveChanges (was Add-but-never-flush); HoSoLink null-safe+clear-via-empty option(b); #70 ||peFetching 2 PRO cells; 413 PASS. Detail → archive/2026-06.md.
  • S89-bis (2026-06-25) AREA-6 FE-consumers (PE FROZEN, investigator verify) — 4/4 confirm + 1 NEW miss: all 4 hold; NEW catch = create-contract joint-winner DEAD-END (FE shows button on some(isWinner) but BE hard-blocks SelectedSupplierId is null). Anti-pattern: single→multi conversion stops at detail-display layer. Detail → archive/2026-06.md.
  • S89 (2026-06-25) AREA-4 workflow-edit (PE FROZEN, investigator verify) — 3 confirm/1 do-not-touch: HoSoLink #73-class clear-on-partial-edit CONFIRMED + NEW 2nd destructive call-site (PeDetailTabs:817 InfoTab.save omits hoSoLink). Anti-pattern: echo-all-siblings convention rots when NEW absolute-set field added. Detail → archive/2026-06.md.
  • S86 (2026-06-24) PE Section B 3-cột Dự-án|PRO|CCM (Mig 59) — PASS: authz byte-mirror UpdatePeSuggestedPriceCcm (NotFound→Forbidden, fail-closed); FE canEditCcm KHỚP BIT-EXACT BE gate; submit-guard untouched (grep CcmBudgetPeriod in Services=ZERO); div-by-0 safe; 402 PASS. Detail → archive/2026-06.md.
  • S82 (2026-06-21) Harness-15-v2 adopt review (0 code) — 3/3 lane PASS: caught 3 MINOR. Memory-note: broadcasts/_index.md sha = notify self-declared content_sha256 frontmatter NOT recompute → don't flag index-vs-file mismatch before reading frontmatter. Stamped-mark mid-session edit OK if only refresh confirmed-decision What-cell.
  • S76 (2026-06-19) PE budget 3-cột Mig 56 + badge — PASS: MAJOR race fixed gotcha #70 (useIsFetching gate). Badge role-set MUST mirror gate bit-for-bit. SURPRISE: spec "KHÔNG migration" FALSE — đọc changed-set thật, đừng tin scope-framing em-main. → _INDEX S76.
  • S72 (2026-06-18) Mig 54 PE giá-đề-xuất + CCM-finalize OPT-IN — financial go-live PASS:* fail-closed guard throw BEFORE set Phase=DaDuyet; finalize-bypass = 3 orthogonal gate + server-recompute amount no-trust-client. → _INDEX S72*.
  • S71 (2026-06-18) Harness-10 run-trace — PASS/GAPS: "TRACKED" 2-level = check-ignore(eligible) vs git-ls-files(committed), model only post git add. → _INDEX S71*.
  • S69 (2026-06-17) Office re-skin + golive authz — PASS: re-skin proof = grep api-call+queryKey sorted -u byte-equal; public-grant = granted root NOT inherit-root (no sibling cascade); accent missing -800 stop = silent no-class Tailwind v4. → _INDEX S69*.
  • S65 (2026-06-16) public HRM Hồ sơ + PE mục E — PASS: upgrade-path MUST MUTATE row (if(!row.CanRead){...}) NOT skip-existing when prior revoke pre-set false (S58-class); menu-hide ≠ API-lock. → _INDEX S65*.
  • S88 (2026-06-25) Fidelity-gate L2 gist distill (test-specialist) — FAIL (1 fabrication-by-merge): gist gán "Mig 45" cho cluster span 2 episode khi chỉ 1 mang số đó (Master = Mig 47). Anti-pattern: merge-distill fabricates false specificity; token-PRESENCE pass BLIND to cross-episode mis-attribution → QUALITY gate after presence gate. Detail → archive/2026-06.md.
  • 2026-07-12 (S112 Supplier Excel-import Phase-B close-review, FE/E2E/DEPLOY lane) [fable-real-single]: GO-WITH-ADJUSTMENTS — detail → project_s112_supplier_import_review.md. Mandatory known adjust = bake ExpectedHeaderTokens (svc:35-67); MAJOR independent catch = FE Import button reuses Suppliers.Create guard but endpoint needs Admin/CatalogManager role → non-functional button for fe-user drafters (BE secure). Deploy dup-risk CONFIRMED safe (4 real NCC ungated-seed Codes=col4 → re-import Update/fill-nulls). Lesson: reusing sibling menu-guard for Admin-scoped NEW action under-restricts — derive guard from ENDPOINT authz. Positive: 24 clamp-consts=EF-len byte-exact, int-enum contract exact (no StringEnumConverter), multipart matches 4 working uploads.
  • 2026-07-12 (S112 PE sign-off approach-review PRE-fan-out+deploy, security/governance lane) [fable-real-single]: GO-WITH-ADJUSTMENTS. (1) EDGE-5 decision-3 hard-lock: spec placement (reject-branch SVC:92 + EnsureCanReject:321 + handler) INCOMPLETE — bỏ sót admin-override path SVC:290 (if(isAdmin) evaluation.Phase=targetPhase) → admin un-terminal DaDuyet bằng decision=Approve (KHÔNG qua reject). Fix = 1 guard TOP-of-method sau var fromPhase SVC:53. Lesson: terminal-lock gác FROM-state ở ĐỈNH method, KHÔNG rải per-branch (per-branch bỏ sót admin/fall-through). (2) CEO-skip decision-2: A1 (creator tự ký ô mình thay auto-bypass) TẠO đường CEO-skip MỚI multi-step-có-CEO — trước A1 bypass advance-qua slot creator (bỏ check finalize); sau A1 creator qua ApproveV2Async → slot có AllowApproverFinalize=true + tick → DaDuyet bỏ CEO (SVC:867). invest-C "đã tồn hôm nay" IMPRECISE (chỉ đúng 1-step-no-CEO). Escalate owner. Lesson: đổi auto-advance→manual-approve = mở lại per-slot flag mà auto-path che khuất — re-scan flag khi đổi ai-đi-qua-code-nào.
  • 2026-07-12 (S112 Supplier Excel-import close-review PRE-deploy, BE+ADJUST) [fable-real-single]: GO-WITH-ADJ. 6 axes PASS: OrdinalIgnoreCase preview+confirm (BuildCiIndex:446/batchByCode:157/seen:158), FillNulls:381-409 skip Code/Name/Type, all-or-nothing gate:137-152 pre-mutate + SaveChanges:188, parser abs Cell:284 (KHÔNG CellsUsed) +#REF!→null:289 +NAS-raw:290 +fingerprint-Ordinal-reject:223, Mig 63 reversible+3-file+snapshot:3330, col→field 30/30 OK (Code=col4 viết-tắt, Name=col5 tên-cty). REQUIRED adjust = bake 30 real token → ExpectedHeaderTokens:37-66 (nguồn test RealFileHeaderTokens:420-451 == brief exact; Case 9 auto-flip). CAUGHT (MAJOR de-risk): Unicode NFC/NFD — test dựng workbook từ literal NFC nên KHÔNG chứng file Excel THẬT accept; đề .Normalize(FormC) NormalizeHeader:306. Lesson: self-flip token-test = internal-consistency KHÔNG external-file-acceptance (artifact ngoài repo = bất-khả-verify).
  • 2026-07-12 (S112 FINAL pre-commit+deploy review — BÓ 2-feature PE-signoff + Supplier-import) [fable-real-single] — VERDICT GO (0 must-fix): Cả 2 close-review adjust ĐÃ áp đúng. F1 PE: EDGE-5 guard đúng ĐỈNH-method SVC:66 (sau fromPhase:53) exempt admin+system, precede CẢ 5 branch incl admin-override:306 (:306 vốn if(isAdmin) nên non-admin không tới) + EnsureCanRejectV2Async:332 untouched; A1 minOwn=Min(Order):607 bypass<minOwn no-auto-sign pointer-stop if(minOwn>1):637 (StepIdx giữ 0 từ submit:265), 4 nhánh cũ (auto-sign/next-Bước/step2/terminal) DELETED; History CHANGE4:751-777 log opinion-cũ→Changelog TRƯỚC 4 dòng overwrite, chỉ non-empty, keyed per-level-row (matchingLevel.Id) → chỉ fire khi CÙNG-NV re-sign, enum Workflow=5/Update=2 tồn. Tests 8-new/4-updated adversarial-grade (EDGE-5 system-exempt chứng qua msg "không hỗ trợ"≠"kết thúc"; history 2-boundary). F2 import: 30 ExpectedHeaderTokens==test byte-identical all-NFC (script verify 0-mismatch); NormalizeHeader FormC:313 áp cả 2 phía; endpoint [Authorize(Roles=Admin,CatalogManager)] = pattern Update/Delete; Mig 63 = 2 nullable additive (prod-safe, expansion-cols từ Mig 62 778fc98 deployed per 4-NCC-in-prod). Nice-to-have (KHÔNG block): (a) test comment :31-37 + svc :31-34 stale "BEST-GUESS chưa khớp" (đã bake) — misleading, harmless; (b) test NormalizeJoin:407-414 thiếu .Normalize(FormC) mà svc:313 có — moot vì token toàn NFC nhưng latent nếu sau thêm token NFD. UAT-visible behavior change (by-design, không phải bug): A1 bỏ auto-terminal-on-submit → TP tạo phiếu-1-bước-tự-là-cấp-cuối GIỜ phải bấm Duyệt thêm 1 lần (trước tự DaDuyet). Lesson: Case-9 self-adjusting (shouldMatch tính runtime) PASS ≠ chứng real==expected → phải diff byte-level 2 mảng token TAY; build/test-green (458) nhận theo claim, review logic bằng đọc.
  • S115 (2026-07-13) /fable-real spec-review presence-not-age adopt (D1 docs + D2 hmw.js STOP-HARD + D3 archive-gate) — PASS-WITH-FIXES (0C/2M/5m): sub = runs/2026-07-13-presence-not-age-adopt/spec-review-fable-real.md. M1: acceptance-grep can't detect its OWN deliverable's miss — D2 crit-4 regex fail-soft.*default subagent\|degrade về default subagent catches only 1/3 doc-lines (misses ultra-on:21 "cảnh báo" + README:208 order fail-soft-AFTER) → 0-hits=false-PASS; fix = bare-token grep + human-classify vs frozen-history, NOT narrow ordered-pattern. M2: "skip element" bolted on contiguous-prefix cut = correctness inversion — naive if protected continue leaves skipped entry ABOVE cutLine → STILL archived while code thinks excluded; needs non-contiguous per-entry byte-sum; DRY-RUN bounds harm but 0 acceptance tests after-est. Lessons: (1) parallel() = runtime-builtin NOT in-repo → premise unverifiable-from-source but design robust-under-BOTH-truth-values = endorse-with-caveat; (2) grep-acceptance must bare-token+classify; (3) verify EACH regex-alt vs EACH real target-line by hand; (4) node --check HAS teeth + top-level return/await pass via CJS wrapSafe (empirical > theory). Spec faithful (3 floors+rec-3+3 honest-notes verified on-disk), scope-clean, honest-caveated; no Smart-Friend lower.

  • S116 (2026-07-13) outward-email GATE se→ai_infra H-22 WAL restart runtime-verify — PASS (0 over-claim / 3 minor): file broadcasts/outbox/ai_infra/2026-07-13-se-to-ai_infra-h22-wal-restart-runtime-verify.md. 6/6 ground-truth re-run MATCH — #1 rev-list=0 · #2 tree clean (modulo email-artifact itself untracked) · #3 HEAD=88bd8e6 · #4 WAL empty-template · #5+#6 EXACT: archive-gate 12/12 sub<25.6KB (tightest investigator-codebase 25237, 363B headroom) + A7 246/246 pointers 0-fail; crystallized 382713B/380K-tok cap/252429-tok headroom. Caveat section STRONG+prominent (own §header "Nấc honest", bold WAL RỖNG/CHƯA, enumerates a/b/c verified vs content-recovery NOT; line31 defers real-persist→S111 Stop-hook×2). No implicit "full restart-recovery verified". Minor: (1) caveat item (a) "WAL persist qua restart" evidentiary-WEAK — .claude/WAL.md git-COMMITTED @88bd8e6 empty-template 0-drift → post-reboot existence = git/filesystem guarantee NOT WAL-mechanism proof (self-corrected by line31 defer-to-S111); (2) unit-notation "382.7KB / 380K-tok" juxtaposes bytes-vs-tokens (382.7KB≈95-127K tok not 382.7K) — looks scarier/understates headroom, "(fits)+252K" resolves; (3) current tree clean modulo email-artifact-itself (untracked). Lesson: persist-claim on git-tracked WAL → verify tracked+0-drift FIRST; "file survives restart" = git/filesystem property, mechanism-persist proof lives at Stop-hook run (S111). No Smart-Friend lower — report well-calibrated toward humility.

  • S117 (2026-07-13) PE negative-quote FE-only spec-review (financial-invariant-owner lens) — PASS (0 blocking, 1 confirm + 2 test-notes): budget-intact VERIFIED — UpsertQuote (PurchaseEvaluationDetailFeatures.cs:282-366) writes 0 budget fields; quote ThanhTien flows ONLY into read-only display aggregates (currentProposalTotal/prevSelectedTotal :911-926 + winnerQuoteTotal :1188) — NEVER mutates PeWorkItemBudget. #81 IsWinner + S114 multi-winner SAFE: winner-derive keyed on IsSelected boolean, sign-agnostic (negative ThanhTien irrelevant). R1 baked (ContractFeatures.cs:46 GiaTri>=0 untouched=manual path; CreateContractFromEvaluation:88-90 no-clamp=PE-inherit). R2 FE:201/BE:206 BOTH SUM(ThanhTien where IsSelected)<=0 = IDENTICAL algebraic sum → 0 divergence from negatives. CONFIRM raised: enterable-negatives OPERATIONALIZE net-value driving CEO-escalation gate (winnerQuoteTotal<CeoApprovalThreshold→CCM skip-CEO) — governance, not display; owner sign-off. T3 note: SeedWinnerWithQuoteAsync seeds 1 quote/winner → "mixed net>0 submittable" half needs multi-quote seed. Lesson: 2-tier guard divergence check = compare SUM EXPRESSION not just comparator; derived-flag safety = trace what flag is KEYED-ON (IsSelected≠ThanhTien); "budget intact" true for RECORD but quote-sum still flows to display+governance aggregates.

@S126 hook-curate batch (2026-07-16, em-main single-writer, moved-not-cut verbatim từ L1)

  • S124 (2026-07-15) adap-wave-reply PLAN L3-lens — PASS_WITH_FIXES (0C/3M/2m): disk sub-reviewer-3.md. 🎯 do-token trap committed WHILE adopting do-token: spec "STATUS=26075 tok (real-N)" — I re-Read FULL → truncation = 70892 tok (tail-alone 33944 > 26075) ⇒ near-cap CHUNK mislabeled whole-file, 2.72× under, feeds owner re-tier. Lesson: verify do-token claim = re-Read full + read truncation line yourself; token count tokenizer-invariant ⇒ 2×+ gap = mis-measure not env. M2 meta-count "6 R1-R6"→5 (R5 highest-value dropped). M3 nấc "verified" on cadence NEVER-RAN (hub-expected = "đã đọc không đổi"). Positives held: authority-class owner-gated correct · harness_floor 55K self-audit honest · all-inherit 14/14. Anti-garble: full disk-write BEFORE return.
  • S125 (2026-07-16) do-token RELABEL correction (em-main on-behalf, B3 append): negative-control 3-probe ('a'×150K→notice "150,006 tokens" ~1,0/char · 'x'×150K→150,006 Y HỆT content-independent · mixed-ASCII 150K→143,251 ~0,955) ⇒ notice-N = heuristic họ-đếm-ký-tự = CẬN-TRÊN bảo-toàn, KHÔNG phải real-token (tokenizer thật nén chuỗi lặp ≪0,1/char). 70892 (dòng trên) đọc lại = cận-trên; dải thật STATUS [31K byte/4 — 70,9K notice]. Lesson sửa-frame: "token count tokenizer-invariant" chỉ đúng cho so-sánh chunk-vs-full CÙNG heuristic; nhãn "real-N" tự nó = mislabel-as-real — phải negative-control (chuỗi lặp) mới phân biệt heuristic/tokenizer. Nguồn: hub phuong-phap-dem-token-tien-de-vong4 + adap-report cùng tên.
  • S125 (2026-07-16) fable-real adap-review — PASS-WITH-SELF-FIXES [engine:fable-real · vai compound anh gán reviewer+inv-cb · inline-lead]: 2 near-miss TỰ BẮT trước khi ra ngoài: (1) false-TAMPER → RCA verifier: PS 5.1 Get-Content -Raw decode UTF-8-no-BOM bằng ANSI → mojibake → hash sai trên broadcast hub SẠCH; sibling-test 2 CHIỀU — sibling-MATCH⇒file-bệnh (tiền lệ S100) · sibling-CŨNG-FAIL⇒verifier-bệnh (S125); chốt bằng stamp_verify.py hub exit-0. (2) suýt claim-sai nguồn outward: draft adap-request viết "snippet hub dùng Get-Content -Raw" — mở hub check-email.md:18 thì snippet để HỞ decode ($txt không định nghĩa) + hub ĐÃ CÓ s76 script-verify → sửa email+request TRƯỚC stamp cuối; email edit-sau-stamp → RE-STAMP 58f5afd8 + selftest exit-0 ×2. Lesson: outward-claim về văn-bản bên kia = mở ĐÚNG file+dòng trước khi viết; email đã stamp mà cần sửa = sửa→re-stamp→re-selftest cùng lượt, đừng để stamp-then-edit sống. Bẫy tooling: Edit-tool 3× fail chèn escape BOM (pipeline sinh-chữ render escape thành U+FEFF thật) → build-from-codepoint. Evidence: runs/2026-07-16-S125-fable-real-adap-review/.

[S128 curate batch — moved verbatim from L1, 2026-07-16 em-main]

  • S124 L2 fidelity-to-source review, adap-wave plan — PWF (0 misread/1 MAJOR/3m): 5/6 broadcast-reading traps read-faithful (NOT-adopt→method/spirit · h17 4-floors-KEEP · r6 abs-path). MAJOR = push-guard "REFINEMENT ahead-of-broadcast" (spec:58) = OVERCLAIM: SE trailing-K is LOOSER than broadcast ahead-range-all-count, keeps sandwiched wal:→leak; NO dimension strictly ahead. run.md:15 + mark cl.4 already carry honest "noise-accepted no-rewrite" ⇒ spec contradicts own run.md+mark. Lesson: "ahead/refinement" = verify vs broadcast's ACTUAL requirement (looser≠ahead); spec+adap-report = shipped artifact → reconcile before hub-send. Verified: adap-reports at docs/governance/ not .claude/ (path-trap false-empty). → archive/2026-07.md.
  • S112 fable-real-single close-reviews+FINAL — GO 0-must: Import btn reuses sibling-menu guard but endpoint=Admin ⇒ derive guard from ENDPOINT authz; EDGE-5 gác FROM-state ở ĐỈNH method KHÔNG per-branch; self-flip token-test = internal NOT external-accept. → topic.
  • S126 (2026-07-16) A1-H23-probe + email-H23-gate [opus ×2, em-main VERIFY+APPEND] — gate FAIL bắt 3 lỗi thật trước stamp: (1) 🎯 "Audit 2/2/0" NON-REPRODUCIBLE — audit COUNTS = session-cumulative, chính 2 lane review đẩy 2→4. Lesson: số AGGREGATE cumulative KHÔNG vào outward artifact mời-reproduce — evidence bền = per-lane theo run-id. (2) "Ba việc nêu ở thư" thực = 2 ASK — MỞ thư đếm ask thật, đừng gộp courtesy-expectation. (3) "hub 17/17" = SE-self-obs R1-open → hedge+quy-thuộc. Lõi verified độc-lập: lead=Fable 116/116 records · A1 fable · A2 opus. Fixed → stamp 945cf3ad selftest+stamp_verify+_index CÙNG lượt. Evidence: runs/2026-07-16-S126-adap-spec-execute/.

[BATCH S134-curate 2026-07-17 — moved verbatim từ L1 MEMORY.md (hook 21.3KB→<17.1KB), move-not-cut]

  • S131b (07-17) GATE#2 outward email-hub closure-cadence follow-up (owner-direction narrate, KHÔNG claim đo mới) — PASS_WITH_FIXES (0C/1M/3m): owner-fidelity vs 2-lượt-chat: "owner tự chỉ ra trade-off" phương-án-A = ĐÚNG (turn-1 owner nói CẢ pro 'giảm nặng start/end' + con 'khó theo dõi hơn' — reviewer NGHI bịa nhưng thật-sự faithful, KHÔNG manufacture) · 4 tiêu-chí trực-tiếp turn-2. 🎯 M1: "nghi-thức chạy tắt HÀNG LOẠT" inflate source chính-xác "3 closeout liên tiếp"/3-session (morning e46863c8 GAP-2) — re-introduce đúng overclaim-class mà morning-gate ĐÃ gỡ (2 fencepost/overclaim); follow-up outward tới bounded-source phải GIỮ con-số của source, "hàng loạt" undo kỷ-luật source đã trả-giá. m2: title quote "không sót" nhưng owner viết "ko xót" (x) — silent spelling-normalize + gloss "im lặng phải khác sạch" commit 1 reading của homophone mập-mờ; interpret probably-correct NHƯNG gate-prompt CŨNG lặp "sót" ⇒ divergence sót upstream = independent-catch. m3: paren-gloss 4 tiêu-chí trộn framework-lead vào section "Owner nhận-định" (hedged caveat-3). Số verify sạch: 250-300K=(ước lượng vận hành)✓ · 6/15 owner-decisions-file+memory-budget:122-123 ⇒ 'số owner đặt' ĐÚNG · eval~0 memory-budget:44 'deterministic NO-API analyzer' ✓. Caveat-block 3-điểm mạnh (chưa-chốt/est-spawn/SE-diễn-giải). Lesson: verbatim-quote owner = so TỪNG CHỮ kể cả homophone x/s; "đã đo" outward chỉ pass khi trỏ disk-measure thật (morning email có).

  • S131 (07-17) GATE outward email-hub + adap-report §6 báo 3 op-gap H24×H22×H1/H2 — PASS_WITH_FIXES (0C/2M-shared-root/3m):topic. MỌI số atomic reproduce (counter=7·S124=3·S128/129/130 no-tick·tick chỉ session-start §2.1.8 [session-end §L.b(j) chỉ ĐỌC]·12 measured·9+4+1 flag·§5(a) flip đúng). 🎯 Bắt fencepost khi số atomic ĐÚNG HẾT: "8 nhãn/+4 (3→7)" ghép lệch cột-mốc (8 nhãn↔+5 baseline post-S123=2; +4↔7 nhãn baseline S124=3) → đọc 84=4-miss SAI (thật 3) → đẻ "gấp-đôi" 2× overclaim (đo thật 8:5=1.6×). Lesson: hero-ratio phái-sinh re-derive từ raw, đừng tin phép-nhân tác-giả; fencepost = liệt-kê từng nhãn + đếm tay.

  • S129 (07-16 đêm) REVIEW adap-errata-EOL 2-lane wf_8a0249f6 — GO-WITH-FIXES ×2: R0 re-verify byte-exact T0/T1 + bắt P1 writer-only = NỬA-VÁ (reader mfe-eval.ps1:193 là read duy-nhất thiếu -Encoding UTF8, đang BOM-sniff; blob mang BOM thật ef bb bf — S87 consumer-sweep áp cho cả ĐỀ-XUẤT-VÁ, không chỉ code) + 2 presentation-gap (blob-mutation không khai · lợi-ích thổi khi porcelain vốn rỗng — S81 class). R1 adversarial: 4/4 cite exact + 2 quick-test tự chạy lại = chứng không-bịa rẻ nhất; tally "7/7 ADOPTED" = rung-flatten 4-gated/3-discipline (S122 memory≠enforcement); story T0 "+1 agent mới" BỊA (delta thật = skills/README.md ngoài glob, số scoped=39); on-behalf verbatim 0-miss (22/22+41/41). Cả 2 lane #53 khai-path-không-ghi → em-main scribe từ journal. Tag [s129, review-adap-errata, half-fix-writer-only, rung-flatten, byte-exact-rerun]

  • S128 (2026-07-16) D-review 2-lane adap 16-07 [hmw reviewer opus-max ×2 · R1 tự-ghi sub-md, R2 return-only→lead scribe; em-main VERIFY+APPEND] — GO-COMMIT 2/2, 0 BLOCKER, owner-gated 0-diff CONFIRMED: R1: 5 acceptance re-run PASS paste-thật · hash 7/7 recompute · 0 self-claim "verified" · M1 evidence-paste "tô-điểm" (contextual_retrieval = False khi lệnh chỉ in False) — soi literal-fidelity CẢ KHI giá-trị đúng. R2: email fact-check 7/7 · counter cumulative AN-TOÀN khi neo file persisted reproducible (≠ S126 self-mutating) · lineage "05-26" → git nói 05-22 bf93abd — lệch CONSERVATIVE ⇒ minor không blocker (direction-of-error quyết mức lỗi outward) · brute-force canonical-variant với known-good TRƯỚC khi phán tamper (recipe strip-1 vs strip-ALL: 2 biến-thể sống chung theo phía phát-hành — SE-set khớp strip-1, hub-set khớp strip-ALL). Lead fold M1+lineage 3-chỗ-cùng-lớp + re-stamp c0ac7486447e. Trace: runs/2026-07-16-S127-adap-dot-16-07/{sub-reviewer-0,sub-reviewer-1,review-synthesis}.md. Tag [s128, d-review, direction-of-error, sha-variant-per-publisher]

  • S128 fable-real #2 re-review spec-execute adap 16-07 [0-garble ghi-đĩa-tăng-dần; em-main VERIFY+APPEND] — GO-WITH-FIXES 4 SHOULD-FIX/0 BLOCKER (cả 4 = lỗi verify-lệnh/scope-rơi): F1 count-quên-README · F2 so _index bằng Get-FileHash = SAI-LOẠI-HASH (body-sha ≠ whole-file, đo 181a6d19f29247cf) · F3 nén draft→spec RƠI item gated cả 2 lane · F4 future-claim S108. Lesson: lệnh verify trong spec = CODE chạy thử trước (2/4 sai thật) · bệnh encoding S125 ở CMDLET không ở shell (Select-String -Path đúng, Get-Content bệnh) · fold = disposition TỪNG DÒNG (S119). Full: runs/2026-07-16-S127-adap-dot-16-07/sub-reviewer-3-verdict.md.

  • S127 fable-real #1 gate đầu-vào adap 16-07 [Fable ~62K tok 0-garble; em-main VERIFY 3/3 + APPEND] — GO-ADAP, BÁC claim hub "bản 2 duy nhất": rag.json:26 override ACTIVE ⇒ bản 5 việc THẬT + bản 3 ≥2 hằng-số sống-bằng-nhãn. Lesson: hedge broadcast phải test bằng MỞ config THẬT · "already-aligned" tinh-thần ≠ luật · SE GIỮ counter đúng (điều-kiện gỡ không áp: 3 tick/2 ngày). Full + AC 8/8: runs/2026-07-16-S127-adap-dot-16-07/sub-reviewer-1-verdict.md.

  • S133 (07-17) pre-commit review pe-budget-freeze [wf_f9c0b939-181, return sạch]: VERDICT PASS_WITH_FIXES — 0 MUST / 2 SHOULD (CÙNG root #81 indirect-writer) / 2 NIT. Catch giá trị nhất: literal-grep 4-site (= PurchaseEvaluationPhase.DaDuyet) PASS hết, nhưng grep .Phase = <biến> lòi 2 đường gián tiếp bypass helper snapshot: WorkflowService:308 admin-override catch-all (= targetPhase) + DbInitializer:1323 seeder (= current; fresh-DB migrate-trước-seed → backfill Mig 67 no-op trên bảng rỗng). Bài: RULE "mọi nhánh set X" phải grep CẢ assignment-qua-BIẾN, không chỉ token enum — #81 mở rộng lên lớp indirect-assignment. 10/10 mục PASS: 3-bản predicate khớp từng điều kiện (kể cả chi tiết Suppliers/Quotes = BaseEntity → SQL đúng khi KHÔNG có IsDeleted trên s/q) · 18-field frozen mapping chỉ rò đúng 2 field cố-ý (pairRec.Id + CurrentProposalTotal live) · R2-hold ✓ · guards đúng vị trí + T5/T6 ✓ · EDGE-5 snapshot-dormant + T9 overwrite ✓ · FE fallback ?? bs.* nằm TRONG nhánh editable đã đóng ✓ · Mig: UNIQUE(ProjectId,WorkItemId) chống row-multiplication LEFT JOIN backfill ✓. Lead áp 2 SHOULD ngay trong phiên: site-5 helper-call + test AdminOverride_DirectToDaDuyet_SetsBudgetSnapshot + seeder demo snapshot + comment gate → suite 520/0. Tag [s133, review-budget-freeze, indirect-assignment-grep, 81-class]

  • S123 governance 4-change review (backtick-guard + H24-3 + retire dạng-3 + mark) — PWF (3 must/1 MAJOR/3m):topic. 🔴 #53 garble tại TAO; đĩa KHÔNG cứu vì chưa ghi diary ⇒ ghi diary TRƯỚC return. Vá-1-lớp⇒grep MỌI matcher cùng-lớp TRONG diff · đổi-format-cho-trượt-mẫu = Goodhart rời-tập-đo.


[BATCH S140-curate 2026-07-18 — moved verbatim từ L1 MEMORY.md (hook 20.7KB→<17.1KB), moved-not-cut]

  • S139 (07-18) L3 review wave adap-3-bản 8-file [wf_65e5cf1e-397 · return CLEAN 0-garble — VERDICT-header-dòng-1 giữ đúng · read-only → EM-scribe sub-reviewer-0.md] [engine: opus-worker]: GO 0C/0M/3-LOW-nit — re-measure MỌI acceptance từ git HEAD, không tin sub-0/sub-1/EM: L1 heading 26/28/7/14 HEAD==CUR + MASTER-CHECKLIST 1/2/1/1 + 10/10 config-token + 3 deletion content-preserving · L2 re-run fault-inject C6 8/8 + H24-4 8/8 byte-exact + live TOTAL=45/exit-0/2-net-0-flag + Test-Quoted CẢ 2 matcher mới (diff:143/:253) + code-point 0-literal-non-ASCII · 4 EM-edit đúng (reviewer.md ĐÚNG-1-từ +grounded — m-3 no-self-exempt: chấm cả edit vào file CHÍNH VAI MÌNH; "4 cấp mark" self-catch của EM ĐÃ GIỮ) · đảo-thứ-tự edits-trước-L3 = SOUND no-new-hole. Nits: sàn-5 vocab-collision session-end :72(🚩H22) vs :108(🔢S138) LOW owner-decidable rename/alias-map · mirror-C1 §2.1.2 thiếu runs/*/run.md (B1-pointer mitigated) · G-011 wording variance. Learned: nhãn "measured" sống qua gate CHỈ KHI falsify-path tồn-tại VÀ reviewer CHẠY nó VÀ nó đứng — 2/2 nhãn wave này grounded thật ("172/185 bare-cites" reproduce ĐÚNG TỪNG CHỮ SỐ bằng grep độc-lập; residual: counter không wired → drift-nit). Surprise: marker-collision M-1 là ca SỐNG trên docs/HANDOFF.md thật (:7 "Prev S134" giữa-dòng vs :9 boundary đầu-dòng) — fix ^-anchor chịu-lực thật trên chính file detector đọc, không phải phòng-hờ lý-thuyết. Tag [s139, l3-go, adap-3-ban, measured-label-grounded, m3-no-self-exempt, san5-vocab-nit]
  • S134b (07-17) pre-commit review lũy-kế tạm-tính [wf_8bb5abee-657 · ghi sub-reviewer-precommit.md — tên RIÊNG tránh đè sub-reviewer-0 của lượt fable-real] [engine: opus-worker]: PASS 0C/0M/4 nice-to-have — 7/7 trục; diff +310/25 (25 deletion = expand-chữ-ký tại chỗ, scope-drift 0%). Positive đáng nhớ: bài #81 CỦA CHÍNH MÌNH (S133) được implementer áp đúng — 5/5 finalize→DaDuyet qua helper (admin-override :311 gate targetPhase==DaDuyet + comment cite #81), seeder :1323 bypass CỐ Ý + set snapshot trực tiếp → 0 changelog D4 rác. Tự chạy lại build+npm×2+filter 8/8 (KHÔNG tin evidence cũ khi diff đổi). 4 nice-to-have = test-backlog: live-fill symmetric-C7 · admin-override D4-path · MaPhieu-null render · PendingSubmitted âm. Learned: (1) "insertion-only + grep '^-'=0" đọc nhanh + chắc hơn diff-mắt cho ràng-buộc bất-động; (2) D4-persist-path soi = trace TỪNG caller tới SaveChanges (5/5 có :301/:316), Add-không-save = row ma. Tag [s134b, precommit-pass, 81-ap-dung, subfile-ten-rieng]

[BATCH S143-curate 2026-07-22 — moved verbatim từ L1 MEMORY.md (hook 26.5KB→<17.1KB), moved-not-cut]

  • S141 (07-20) fable-real gate SPEC adap đợt-9/10 — GO-WITH-FIXES 0C/7M/9n [engine: fable-real · model claude-fable-5 spawn-param-thắng data-point mới · wf_25210715-f7d · 0-garble, sub-file ghi-trong-lúc-làm]: spec-review 5-trục trên spec THIẾT-KẾ (chưa có diff) vẫn bắt 7M thật. M3-class: 2 site roster-count sống nằm NGAY TRONG 2 file spec ĐANG sửa (session-start:97 + session-end:142 "4 monitor") — 5-lane invest + lead đều sót vì grep token "roster 14" MISS site viết "10 … + 4 monitor" ⇒ sweep same-CLASS (mọi cách viết count) không chỉ literal. M2-class: detector MỚI phải kiểm luật owner TẠI CHỖ trước khi quyết TOTAL (governance-detectors.ps1:65-68 "brand-new net → INFORM-sink day-one" — spec quyết ngược không reconcile). M7-class: sửa prereq-stale (b) mà bỏ (a) cùng-đợt-về = tạo stale MỚI cùng class đang vá. M1: FI ca "giảm-counter" bất-khả-FLAG nếu detector thiếu nhánh regress — acceptance phải falsify được TỪNG biến-thể. Fidelity-check 7 thư: FAITHFUL + 2 form-deviation có-chủ-đích (alias-model n1 · Light-skip M4 → carve-out-class cần lưới+khai-nấc). stamp_verify.py hub tolerant từ Jul-3 — thư 07-17 chỉ codify cái đã chạy. Tag [s141, spec-gate, same-class-sweep, inform-sink-day-one, prereq-pair-flip]
  • S134 (07-17) SPEC-review pre-code PE lũy-kế — GO_WITH_FIXES 0C/2M/9N [detail → run sub-reviewer-0.md]: M1 spec đặt "không đổi X" phải tự-kiểm mọi field bắt-buộc của việc-mới có đủ nguyên-liệu trong X-nguyên-trạng (helper thiếu actor param ⇒ hmw tự thêm = VỠ acceptance A6) · M2 claim-hành-vi-FE phải trace về biến trong predicate, không tin câu-văn · SHA 6-file TỰ-ĐO = trọng-tài khi 2 nguồn lệch (47c97df15534addb). Tag [s134, spec-review, constraint-self-consistency, banner-gate]

2026-07-17 S138 — review spec wave 3-bản (engine fable-real · #53-GARBLE → entry ON-BEHALF, lead ghi sau VERIFY-đĩa từ transcript-forensics wf_a0aa62f5-9e8)

  • Task: adversarial review spec v1 wave adap 3 bản AI_INFRA 17-07 — chạy 36 tool-use/208K tok, đọc TRỌN spec + sub-invest + 3 bản + 5 script đo + detector + 4 cửa + 5 re-count, chết TRƯỚC khi soạn verdict (StructuredOutput không gọi).
  • Verdict (em-main-solo gate thay — KHÔNG phải phán của vai này): GO_WITH_FIXES 3M/3m/1n; 2/3 MAJOR đến từ chính re-count của lane trước khi chết (HANDOFF:7 "Prev S134" giữa-dòng → boundary phải ^**Prev S · STATUS In-Progress toàn lineage → scope HANDOFF-only). Chi tiết runs/2026-07-17-S138-adap-3-ban-17-07/review-synthesis.md.
  • Learned: wf-agent chết KHÔNG resume được SendMessage ("No transcript found") — thang recovery wf-lane = disk → journal → transcript-forensics → em-main-solo; re-count của lane chết = evidence dùng được.
  • Surprise: marker-collision — file HANDOFF hiện-hành chứa chuỗi "Prev S134" giữa dòng NEXT-anh ngay ngày detector được thiết kế (boundary-marker trùng mặt chữ nội dung, cùng họ citation-trap S123).

2026-07-18 S140 — FIDELITY GATE sleep-compress L2 (5 gist DRAFT vs verbatim, Phase 3b G-001 lead-no-self-grade)

  • Task: chấm 4-trục (bịa/drift/keep-drop/coverage-token) 5 cặp gist-draft↔archive/2026-07.md {cicd·tooling·inv-cb·harvest·reviewer} TRƯỚC khi lead Write chính thức.
  • Verdict: FIDELITY FAIL — 1/5 pair FAIL (investigator-codebase) + 4 PASS. inv-cb FAIL trục-3: "Drop thấp: 0" là CLAIM SAI — 2 recon-cluster verbatim THIẾU HẲN khỏi gist: line 31 S71 run-trace (TRACKED-2-level check-ignore-vs-ls-files · G-015 containment-shift H2→H10 · path-trap runs/22-tracked) + line 28 06-20 governance landing-map (harness-11-engine canonical D5-D10 · Harness-14 keep_floor=5/golden-set-14q). Grep độc-lập xác: gist 0-match cả 6 token, verbatim :28/:31 CÓ. Author gộp 3/5 sub-cluster của S125-batch (Office/PE-recon/FROZEN-Mig59) nhưng bỏ 2 → Drop-thấp overstate. Minor: 17.5KB(LIVE) mislabel self-target(thật 17.1) · AREA-2 PeSuggestedPriceFeatures.cs:153-199 dropped.
  • 4 PASS: cicd (20 run-record→6 CỤM; gate-chain Infra 413→464 / tổng 458→509 arithmetic khớp; A/005-008-010 + endsBeforeCeo flip exact) · tooling (12-dp model-chain + D-BUNDLE-lag + permission-matrix-Session6 exact; D51OYyGV/BVdssm5S nghi-bleed-từ-cicd nhưng THẬT ∈ tooling-verbatim :54 STATUS:27-pointer-history = 0-bleed) · harvest (7 block-md5: 5 khớp verbatim-header + 2 L1-only HONEST-disclosed ⚠; minor CỤM10 self-compact "S114"→thật @S113-end + list thiếu S123/S125-exec nhưng token-layer đủ) · reviewer (45-rec→9 CỤM, CỤM9=catch-all nên Drop-thấp-0 ĐÚNG; verbatim tự-lệch service:871-vs-873 → draft resolved-đúng-873).
  • Learned: "Drop thấp: 0" là claim FALSIFIABLE — grep từng June-recon-cluster curated-into-July xem gist carry chưa; 4/5 carry đủ (reviewer nhờ CỤM-catch-all), inv-cb chọn-lọc 10-nhóm bỏ 2 recon-infra mà vẫn khai 0. Per-file bleed test = token gist-X phải ∈ verbatim-X (không phải chỉ ∈ 1 verbatim nào đó); D51OYyGV cứu bởi pointer-history-line. Tag [s140, fidelity-gate-sleep-compress, drop-thap-claim-falsifiable, inv-cb-fail-2-recon-cluster, per-file-bleed-pointer-history]

2026-07-18 S140b — GATE OUTWARD email SE→ai_infra pre-stamp (G-015 no-overclaim, năm-vòng report)

  • Verdict: GO_WITH_FIXES (2 minor + 1 opt). Claim-by-claim vs đĩa/transcript phiên NÀY: Vòng4 (fidelity 4-PASS+1-FAIL+CỤM11+grep-6-token-0-match) GROUNDED — gist committed aa88d01## CỤM 11 :46 + 6 token :47/:53 + Drop-thấp honest-disclosed (= CHÍNH việc tao lượt trước) · Vòng5 (probe 5-nhãn measured/empirical/calibrated/grounded/đã-đo 0-tool 17s) GROUNDED = CHÍNH TAO + lead-view-auditor:15 agentId a56dcf6da…+17s · Vòng2 (light-audit#3 counter14 → 1 LOW view-stale + 1 MED gap-owner) EXACT = lead-view:15+lead-omission:17 · last_sleep 07-10→07-18 EXACT (aa88d01~1 vs HEAD) · 0b0285c msg confirm H2 6/6+H1-1-drift · session-model-se-draft.md tồn (7779B).
  • Fix-1 (precision/measured-label): 68.968B = DRAFT-total (reviewer draft 15777) nhưng SHIPPED .gist.md=69175B (reviewer +207 draft→final; 4 agent kia draft==final) · 183.054B vs git-blob 183005 (<0.5%, CRLF/method). Honest-note (iv) đã round "≈183→69KB" ⇒ nới precise-figure về rounded HOẶC re-Get-Item final .gist.md. Fix-2 (semi-overclaim): "2 FLAG đều đã xử trong phiên" — diary: LOW=xong-chờ-closeout-clear · MED gap-owner-specifics resolve=PENDING (tracker/owner-defer) ⇒ reword "triage/nêu-hướng" chứ không "đã xử". Opt: 291550ff (assert 2-chiều) = SE-internal hash, ai_infra khó resolve.
  • Learned: measured-label "68.968B" = draft-stage stale — số-đo phải trỏ artifact SHIPPED (committed .gist.md) KHÔNG draft-scratchpad; nhưng direction nhỏ (<0.5%, compression trông tốt hơn tí) + honest-note (iv) round sẵn ⇒ minor không FAIL (S128 direction-of-error). Outward-gate mạnh nhất khi claim = việc-CHÍNH-TAO (Vòng4/5) → re-measure by-construction. Tag [s140b, outward-gate-go-with-fixes, measured-draft-vs-shipped, semi-overclaim-da-xu-pending]

2026-07-22 S145b-curate — moved verbatim from L1 (S145a FAIL + S143 outward-gate); L1 digested to pointers

  • S145a (07-22) gate GOVERNANCE-roster +1 vai-KIỂM tooling-harvest-audit (C4 TÁCH, adap dot-11, roster 17→18) — FAIL 3M/4m. 🔵 Công bằng: CORE wiring THẬT tốt — role-file mirror harness-audit đủ (no-self-exempt m-3 · thách-CLEAN · tái-dựng ≥1 số CÓ-THỂ-SAI · fail-safe NO-OP · C4b mtime), session-end (g-bis) AUTO đúng (KHÁC (j)H24/(k)trio consent), STATUS 17→18 + cell + "Cả 7→8 monitor" + hmw.js VALID_ROLES (node --check OK) + dual-surface registry, axis 4 verified-pending-restart KHÔNG over-claim, axis 5 incremental (0 file h24-audit/sleep-audit). CLASS MỚI = TÁI-PHẠM-BIẾN-THỂ của chính S141-S143: wave đó giết NAME-enum blindness ("ĐẾM PHẦN TỬ đừng grep SỐ") — nhưng lần này drift chạy TRỐN sang NUMERIC hardcode "roster 17": fable-clone.md:3+:18 · fable-real.md:3+:19 (argument-hint + heading, roster gồm monitor per :21) + README:276 narrative → 4+1 site stale (→18). ⇒ LUẬT: sweep repo-wide phải grep CẢ \bN\b (folder|vai|roster|sub) NUMERIC LẪN name-enum, KHÔNG chỉ site count-free mình sửa. M-2 harness-11-engine.md:345 name-enum thiếu vai mới + tự xưng " VALID_ROLES = ĐỦ roster … trọn roster (14→17)" = ĐÚNG class README:225 S143 (completeness-claim self-referential, đã update @S141 mà quên @S145). M-3 README skill-matrix :186 thiếu row vai mới (trio có row từ S141). Measured-label gate BẮT: WAL tự khai doc-sync 8-enum … self-verify 0-stale — "0-stale" là nhãn kiểm-chứng, FALSIFIED bằng grep repo-wide (self-verify chỉ scoped 8 site ĐÃ SỬA, KHÔNG repo-wide = đúng bệnh "sweep sạch sau khi grep subset" S143). 🔸 Pre-existing (phân-loại RIÊNG, KHÔNG tính lỗi change): sleep-recovery-memory-l2.md:42 "4 monitor" thiếu CẢ trio (S141) lẫn vai mới (unmodified ⇒ predate) · engine:332 GAP-1 lineage dừng S121 (thiếu trio). Tag [s145a, governance-roster, enum-sweep-incomplete, numeric-roster-count-stale, name-enum-killed-numeric-survived, self-verify-0stale-falsified, core-wiring-clean]
  • S143 (07-22) gate OUTWARD wave đợt-9/10 (email ĐÃ GỬI + 7 adap-report) — FAIL 1C/4M/4m/1nit [#53 garble lượt-1 → vớt TRỌN từ sub-file; "ghi-đĩa-trong-lúc-làm" cứu lần 2] — chi tiết đầy đủ → runs/2026-07-22-S143-closeout-audit/sub-reviewer-0.md. CLASS MỚI bằng-chứng-tự-huỷ-sau-squash: 5/7 report neo evidence vào wal: commit TIỀN-closeout (1a0fa59/a458102) → squash làm dangling (branch --contains RỖNG, is-ancestor origin/main exit 1) dù cat-file=commit ⇒ hub không resolve nổi; nội dung vẫn có trong 2757e41 ⇒ chết CON-TRỎ, không chết việc. Đối chứng: wave TRƯỚC cite 7760cdf/da349fc (commit ĐÍCH sau squash) → sống hết. LUẬT: cite trong outward = commit SẼ SỐNG sau squash, KHÔNG BAO GIỜ wal:. Cùng class: is-ancestor exit 0 → OK-reachable lật exit 1 trong cùng phiên; evidence-paste NHIP-NO … run-chua-gom 0 nay ra 4-vế. git status --porcelain là bước ĐẦU của outward-gate, không phải bước cuối — lòi M scripts/nhip-no-probe.ps1 (+55/-2, mtime SAU push) làm SAI câu "Chưa làm, chờ owner" trong THƯ ĐÃ STAMP. Số publish phải neo mốc: khai TOTAL 46, live 47, baseline repo 45 ⇒ tách claim-DELTA (đúng, có Compare-Object) khỏi claim-TUYỆT-ĐỐI (thối theo giờ). Tái-phạm same-CLASS-sweep — bài S141 của CHÍNH TAO: "TRIPLE 17/17/17" đúng ở README:236 nhưng site tự xưng "VALID_ROLES … ĐỦ roster" (:225) còn 14 ⇒ chọn enum DỄ. First-person evidence: frontmatter reviewer.md 0 Write/Edittao vừa Write+Edit thật ⇒ claim "whitelist = tuyên-bố ý-định, không phải cơ-chế" GROUNDED. 🔵 Công bằng: 15/17 số tự đo KHỚP, kỷ-luật nấc G-011 (0 thư khai verified) là hàng THẬT — lỗi ở lớp artifact, không ở việc. Remedy = errata, CẤM sửa file đã stamp (vỡ hash). Tag [s143, outward-gate-fail, evidence-self-destruct-squash, cite-post-squash-commit, git-status-first, absolute-number-needs-anchor]

2026-07-22 S145-curate (lane-4 self) — moved verbatim from L1 (S145 lane-4 Axis-D + S145 C7-lane Axis-A + S145b gate); L1 digested to pointers

  • S145 lane-4 (/fable-clone Axis-D 5-vòng-closure) review SPEC apply-hub — PWF 2M/1m. Owner-asked D2 RULING: DEFER (session-start KIỂM gap) LEGIT — canonical "hai đầu" nhịp binds MEASURE fn (H1 "báo diff vs last-session" session-start.md:127 ✓ both-ends + em-main VERIFY→APPEND B3), NOT the new KIỂM layer; canonical self-verify col V1/V2/V4 = CLOSE-time ("commit đóng phiên gần nhất"/"ba lần đóng phiên gần nhất") ⇒ 3 KIỂM session-END-only = canonical-CONSISTENT (arguably CORRECT reading). Contrast: harness-audit V3-KIỂM IS both-ends (consent). 🔴 phép-4 LANDMINE live-on-disk (ESCALATE S145b minor→FAIL-risk): agent-memory/tooling-harvest-audit/ EXISTS-but-EMPTY + h24-audit/+sleep-audit/ folders MISSING; tooling-harvest-audit AUTO-fires this close (session-end.md:118 no-consent) ⇒ run-mà-ko-write-sổ = phép-4 "vai-đã-chạy-có-sổ" FAIL NGAY closeout này. FIX-2: D1 "(bảng verify)" quá lỏng — phải SHOW per-check disk-evidence (cửa-count·dòng-nợ-line·3-closeout-trace·vai-sổ-list) ko bare "PASS". FIX-1: D2 "documented" unsatisfiable — spec route quyết cho lane-4 mà ko NAME nơi defer-rationale land (review ephemeral≠durable); +coupling h24-audit "AUTO sau H24" nhưng H24 chạy BY-CADENCE tick session-START §2.1.8 ⇒ cadence-at-open H24 un-audited. Root = session-end.md:123 "incremental #2/#3 land dần" MÂU-THUẪN :41-42 "AUTO wire cả 3". LESSON: acceptance chứa "vai-có-sổ" ⇒ MUST ls agent-memory/<role>/ on-disk (folder tồn-tại ≠ có MEMORY.md). Mapping 5-vòng→KIỂM verified REAL (7 agent files glob, ko doc-trust). Tag [s145, fable-clone-lane4, axis-d, defer-ruling-legit, phep4-empty-folder-landmine-live, measure-both-ends-vs-kiem-end-only, canonical-self-verify=close-time]
  • S145 C7-lane (/fable-clone Axis A) — PWF, 1 CRITICAL conflation caught. Spec "đính-chính stale 4 surface→2" cho nhip-no-probe.ps1:6-7 header = FALSE: verified 4 caller THẬT (pause:44·tiep:112·session-start:216·session-end:104 — 3+4 là khối "BÁO dòng-nợ 4-vế" LIVE, KHÔNG deprecated); header TỰ-KHAI "4 surfaces (/pause /tiep session-start session-end)" = ĐÚNG. Spec-author conflate 2 script cùng đuôi *-probe.ps1: thấy session-start/end gọi distill-shard-probe.ps1 (ĐÚNG, sleep-check session-start:135) → suy sai "⇒ KHÔNG gọi nhip-no-probe" (gọi CẢ HAI, khác mục-đích). session-model-se-draft.md:34 "4 điểm lệnh" cũng ĐÚNG. Acceptance A2 grep "4 surface"=0-hit = ANTI-TEETH Goodhart — cổng PASS bằng XÓA info ĐÚNG, thưởng việc làm doc SAI (lớp "vá bằng rời tập-đo"). Fix = DROP step-4 + A2-stale-clause, GIỮ "4". LESSON: (1) "stale-fix"/"đính-chính" claim phải verify caller THẬT trên đĩa TRƯỚC khi tin — script header tự-khai caller-list = data-point kiểm được, đừng tin suy-luận spec-author; (2) 2 script cùng naming-pattern = conflation-vector, grep EXACT script-name không đủ, phải đọc caller-block xác mục-đích. Core C7 sound: law-home engine §N (không command, B1-point ) + fault-inject chiều-lỗi teeth (A3 falsifiable, minor=chốt inject-vector) + code KHÔNG đổi (catch:203-208 exit0 thoả vế-iv). Tag [s145-c7-lane, conflation-2-probe-script, anti-teeth-goodhart-grep, header-selfdoc-verifiable, stalefix-claim-must-verify-disk, PWF]
  • S145b (07-22) gate GOVERNANCE-roster vai-KIỂM #2/#3 h24-audit+sleep-audit (C4/C4b TÁCH, roster 18→20) — PASS 1m. POSITIVE-VALIDATION: implementer VÁ ĐÚNG mọi finding vai#1 S145a + tự mở rộng sweep: de-number fable-clone/real argument-hint+heading ("roster 17"→"roster"), fix harness-11-engine:345 completeness-claim "14→17"→"17→20"+trọn-roster, +3 skill-matrix row, +3 decision-tree branch; PLUS tự tìm-diệt 2 NUMERIC site NGOÀI checklist (vocab-alias-map "17/17"→"TOÀN-ROSTER" · README auto-toan-vong "roster 17"→trỏ-canonical) = bài "grep NUMERIC lẫn name-enum repo-wide" S145a ĐÃ NGẤM. Axis4 CLEAN: STATUS 20 + hmw VALID_ROLES 20/20 (bidirectional cross-check mọi agent.md↔VALID_ROLES = 0 MISS) + README×6 + subset-enum-detector (đếm 1-2/3 per-line) xác nhận mọi ROSTER-enum FULL(3/3), 7 "subset" đều per-role hợp-lệ (decision-tree/skill-matrix/VALID_ROLES split 2-dòng). Role-file mirror đủ (RANH SẮC h24 "KIỂM con-đo H24 KHÔNG soi-lead trực-tiếp" · gist-ADDITIVE invariant · fail-safe NO-OP · JSON-pin THẬT: flag_classes=11/h24_cadence/class_repeat tồn-tại). Wiring: (ii-bis) AUTO sau cặp H24 KHÁC (ii) consent-gate H24 (khai thẳng, KHÔNG mâu-thuẫn) · Phase4.5 sau Phase3-Fidelity+Phase4-WRITE trước Phase5. Axis5 no-over-claim (executed/verified-pending-restart; counter "KHONG H24 audit phien nay"=khớp NO-OP). 🔸 1 MINOR — measured-label gate: README:249 "cả 3 hiện chưa có folder ⇒ 17 folder vật-lý là đúng" FALSIFIED bằng ls agent-memory/ = 18 dir (tooling-harvest-audit/ RỖNG tồn-tại từ phiên này); nhưng 17 dir CÓ MEMORY.md + git KHÔNG track empty-dir ⇒ committed-state=17 khớp enum ⇒ low-impact, fix=reword "17 folder-có-MEMORY". LESSON tự-thân: regex/bracket-count trên hmw.js VALID_ROLES DỐI (non-greedy [\s\S]*?] + bracket-depth-parser CẢ HAI trượt vì [2]/[S110 trong comment → báo "18/0" giả) ⇒ đếm VALID_ROLES = per-file grep bidirectional (agent.md↔literal), KHÔNG regex. Tag [s145b, governance-roster-followup, PASS, vai1-lesson-absorbed, numeric+name-sweep-repowide, folder-count-vat-ly-falsified, regex-on-hmw-unreliable, bidirectional-crosscheck-wins]
  • S145 Axis-E lane (/fable-clone tiep/pause/snapshot + CROSS-CUT) review SPEC apply-hub — FAIL 2C/1M/4m. Corroborated Axis-A lane CRITICAL independently: A.4/A2 "4 surface→2" FALSE (grep scripts/nhip-no-probe.ps1 = 4 caller pause:44·tiep:112·session-start:216·session-end:104; A2 grep-0-hit = anti-teeth Goodhart). UNIQUE to Axis-E = 2 seam-catch 4 lane kia RƠI: (CRITICAL-2 C↔E) Axis C.2 hook 3→4 path (+sessions/) phá Sàn-3 tiep.md §0 — "3 path"/"3 điểm mù" hardcode 4 site (:21/:23/:75/:78); sau +sessions/ ⇒ (a) 4 stale, (b) BẬC-MẠNH signal④ chỉ phủ runs/ ⇒ sessions/ orphan KHÔNG signal = reopens "sổ trống≠sạch" blind-spot ON THE SAFETY-CRITICAL RECOVERY FLOOR, (c) BẬC-TRUNG :75/:78 "bẩn ngoài 3 path" misclassify sessions/-dirt (logic bug THẬT ko chỉ prose). Đã biết: adap-report 07-17:23 "meld-forward-gap (hook 3 path vs manifest 4)". Cả C.death-path(spec:33) lẫn E.death-path(spec:47) KHÔNG nhắc ripple = gap ĐÚNG khe 2 lane. (MAJOR-3) C.1 session_ctx_kb=64 nghịch owner-authority: 4 artifact phiên trước phân-loại OWNER-GATED + K6.2 CẤM "mượn số hub chưa đo" (session-model-se-draft:55); spec cite "canonical default" KHÔNG cite owner-directive + acceptance C1 ko đòi _owner_set lineage (bulk=30 CÓ); + ghost-wire #H18: 0 script đọc session_ctx_kb (pull_warn_days mà spec analogize thì CÓ reader nhip-no-probe:190) ⇒ analogy hỏng 2 mặt. LESSON cross-cut lane: bất-biến chia-đôi giữa 2 axis (hook-path-count ⟂ Sàn-3-blind-spot-count) nằm ĐÚNG SEAM, mỗi lane-đơn thấy nửa → chỉ cross-cut sweep bắt; "áp hub-answer" (bulk/C7 hub-trả) ≠ "số owner-giữ" (session_ctx_kb SE CỐ Ý từ-chối) — đừng gộp. Tag [s145-axisE, crosscut-seam-catch, hook-4path-breaks-san3-recovery-floor, session_ctx_kb-owner-gated+ghost-wire, corroborate-4surface-critical, FAIL]

@S155-curate (2026-07-27) — moved verbatim từ L1 MEMORY.md (hook 23.9KB → <17.1KB)

  • [verbatim → git 8b6df0a closeout] S146 (07-22) PRE-COMMIT spec-v2-applied (governance 20 file) — 2 MAJOR THẬT (cả hai của LEAD); nấc verified tự-chạy-lệnh không-tin-lead: F1 session-end.md còn hook-3-path GẠCH-NỐI dù worker CE đã chỉ đích-danh (class "residual có người chỉ tận nơi vẫn rớt") + bất-đối-xứng nội-bộ (pause.md đã 4-path). F2 phép quét cardinality của lead siết LỆCH-TRỤC (co-occurrence CÙNG-DÒNG + 1 mẫu-chữ) → re-run HEAD tiền-vá lọt 4 ca thật gồm chính F1. F3 HELD (git show da7ee8a: hook 4-path + -File re-đọc mỗi Stop). 🔴 Bài rút: lead sửa 1 phép quét 4 lần/phiên vì mã-hoá ý-định NGỮ-NGHĨA vào regex; nấc đúng = lưới-soát-cho-người + allowlist CÓ TÊN + use⟂mention; lần-4 = citation-trap (dò bắt chính nốt-vá vì nó trích giá-trị cũ).

  • S147 (07-23) DIAGNOSIS-review PE attach TraLai (no diff — verify root-cause + stress fix) — Diagnosis PASS 5/5, fix CORE-safe/EXT-unsafe: 5 claims verified from disk; BE-no-guard CONFIRMED intentional by S78 changelog L9 ("handler KHÔNG guard drafter-only → approver upload no-403") + sole pipeline behavior=ValidationBehavior. 🔴 MAJOR blind-spot: attachEditable=isDrafter&&isEditablePhase SAFE for GeneralAttachmentsSection (:2013 readOnly=raw, no carve-out) but UNSAFE for SupplierAttachmentsCell (:2758) whose readOnly=itemsReadOnly (readOnly&&!approverEditMode, Mig28-F3 ChoDuyet approver-edit) → naive REPLACE breaks approver QuoteDocument edit in ChoDuyet; SAME gap in optional BE guard (carve-out {ChoDuyet+ApprovalAttachment} misses ChoDuyet+QuoteDocument). Scope trap: isDrafter@:140 in MAIN scope, OUT-of-scope at :2013/:2758 (child comps take only {ev,readOnly}); changing :421 over-broadly hits HoSoLinkRow:2017. Completeness: WORKSPACE (readOnly=false, picker editableOnly∋TraLai) already edits comparison-doc in TraLai → bug is LIST-detail-only (:574/:669 hardcode). LESSON: decouple a gate → trace if shared prop already carries a carve-out (itemsReadOnly ≠ raw readOnly); "same fix" for sibling surface may hit a DIFFERENT gate source.

S152 (2026-07-26) — D2 Fidelity-gate 6 gist "CỤM BỔ SUNG" (coverage-diff) — PASS_WITH_FIXES (A/B/C/D PASS · E FAIL)

  • Census thay spot: 307/307 trích có trong verbatim CẶP (275 exact + 32 sau khi hoàn '"), 307/307 chứa ĐÚNG token gắn nhãn, 307/307 token thật-sự VẮNG khỏi gist tiền-append (0 gap thổi-phồng). ref=46 khớp đúng claim lead. Trích = cửa-sổ ~150 ký-tự cố-định, token ở ~27% → cắt giữa từ ở 2 biên nhưng payload (file:line/finding) còn nguyên ⇒ điều-hướng được, KHÔNG rác.
  • 🔴 E FAIL — class-gap hệ-thống, chữ-ký sạch: máy-trích emit file-ref CHỈ cho {.cs 101/.tsx 45/.ts 16/.ps1 8} = 170 token, ZERO cho {.yml,.json,.slnx,.csproj,.sql,.config} ⇒ 13 token infra vắng ở 5/6 cặp. Nặng nhất: deploy.yml (chính file pipeline, trong gist của vai CI/CD!) · appsettings.Production.json (16 lần trong verbatim) · 2× s59-*.sql (chạy TAY prod ngoài pipeline) · memory-budget.json (single-source canonical CLAUDE.md). Header cụm TỰ đặt chuẩn "file-ref phải sống trong gist" mà KHÔNG khai N/A ⇒ trượt bằng chính thước mình.
  • 🔴 3 THƯỚC-HỎNG (bug ở phép đo, không ở vật): (1) md5 disk vs git show — spec gate ghi vậy — báo FAIL GIẢ 3/6 verbatim do worktree CRLF ⟂ blob LF (autocrlf=true + 188 file legacy i/lf w/crlf); đúng phải git diff HEAD --quiet hoặc strip-CR 2 phía. (2) grep -c distill-gen vô-dụng vì CHÍNH header cụm chứa chữ "distill-gen giữ" (citation-trap nhẹ) → phải so VALUE distill-gen:\s*\d+. (3) grep -iF trên MSYS trả 0-hit im-lặng cho pattern ASCII trong file UTF-8 (Mig42: -F=1 nhưng -iF=0) = bẫy vắng-mặt-trông-giống-sạch S146 — thoát nhờ đối-chiếu Python.
  • Tự bắt 2 lỗi của CHÍNH mình trước khi báo: "Mig 47/50/42/46 MISS" = artifact chuẩn-hoá của tao (Mig42 liền không dấu cách, có ĐỦ 2 phía) · context-regex .{70} trả RỖNG đọc nhầm thành sạch → phải .{0,70}. ⇒ LUẬT: mọi MISS phải literal-grep XÁC-NHẬN 2 phía bằng công-cụ THỨ HAI trước khi vào report.
  • D re-ground từ đĩa: docs/gotchas.md count=83/max=83 ⇒ 0 nhãn gotcha #N>83; soi NGƯỢC 24 dòng gotcha ≤83 tìm mirror-error (run-number đội lốt gotcha) → 0 ca, mọi #N đều là gotcha thật trong ngữ-cảnh nguồn. Tag [s152, d2-fidelity-gate, coverage-diff, extractor-ext-blindspot, thuoc-hong-x3]
  • S155 (07-27) DIFF-review đợt 1 tiền-DEPLOY (PE delete-approver, 14 FLAG 4H/6M/3L/1I) — DEPLOY-CÓ-RỦI-RO: 🔴 class MỚI HIGH nằm ở git chứ không ở mã — 2/3 file migration UNTRACKED (?? …AddPeAllowApproverDelete.{cs,Designer.cs}) trong khi snapshot đã trackedgit commit -a/add -u nạp model-có-cột mà bỏ migration ⇒ DbInitializer.cs:64 MigrateAsync() không thấy gì để áp ⇒ Invalid column name cho cả 7 module dùng schema V2. Build+test đều xanh, local đã áp mig ⇒ 0 dấu vết. LUẬT: gate deploy phải chấm git status ^?? cho Migrations/, không chỉ chấm diff. · H ExecuteDelete ngoài transaction TRƯỚC SaveChanges = mất chữ ký không hoàn tác (đếm được 4 nguồn ném nằm giữa 2 mốc ⇒ đường nổ có thật, không giả định) · H purge xoá CỨNG chữ ký của phiếu mới XOÁ MỀM ⇒ phá thẳng "khôi phục phiếu" của chính đợt 2; và test :607-609 đang KHOÁ chiều ngược (Should().Be(0)) ⇒ cảnh báo trước cho wave vá: đỏ ≠ hồi quy, cấm nới assert · H ~600 dòng BE = mã chết: grep api.put = 0 hit, Designer chỉ POST ⇒ đúng mục tiêu §F.0 (cứu phiếu đang treo) KHÔNG dùng được trong UAT.

    • XANH-GIẢ bắt được bằng phép 2-thế-giới: F16_…NoPeChangelog assert PurchaseEvaluationChangelogs.Count==0 nhưng test seed 0 phiếu PE ⇒ còn-gate và bỏ-gate cùng cho 0 ⇒ phép đo không phân biệt được 2 thế giới = 0 thông tin. Cách bắt: truy MỌI write-site của bảng được assert, rồi hỏi "bỏ guard đi thì quan sát có đổi không?"
    • CLEAN có răng (không "đọc thấy ổn"): bất-biến Version/IsActive/Id chứng bằng liệt kê vét cạn grep "def\.[A-Za-z]* *=" = đúng 3 write (Name/Description/UpdatedAt) + sweep gián-tiếp (= def;/SetValues/Entry(/CurrentValues) = 0 hit ghi (hit duy nhất là READ trong string nội suy) — đúng lớp gotcha #81-EXT · 11 đường lách thử, tắc cả 11 · double-insert DbSet.Add+nav.Add = 1 entity, và đã có test bắt nếu sai (F12 assert đúng 2 row) · bán-kính đo NGƯỢC từ config: grep OnDelete ra đúng 7 FK Restrict = khớp 7 bảng handler quét.
    • 2 lỗi CỦA CHÍNH TAO tự bắt: (i) lần đầu trích line-number từ diff thay vì từ đĩa ⇒ sai toàn bộ, phải re-grep sửa lại (LUẬT: git diff không mang số dòng file — mọi anchor phải grep từ đĩa); (ii) ls | grep -v Snapshot ăn nhầm AddPeApprovedBudgetSnapshot ⇒ tưởng thiếu file migration — thoát nhờ đối chiếu __EFMigrationsHistory (S152 luật "MISS phải xác nhận bằng công-cụ THỨ HAI" ăn thật lần nữa).
    • File bị sửa TRONG LÚC soi (mtime lệch 71s — wave vá song song): anchor ≤:659 giữ nguyên, sau :660 trôi +21. LUẬT: review file đang-được-sửa ⇒ ghi bản-đồ-trôi + neo bằng NỘI DUNG DÒNG, đừng chỉ số. Tag [s155, diff-review-pre-deploy, untracked-migration-gate, executedelete-no-tx, vacuous-test-two-worlds, anchor-drift]
  • S155 (07-27) SPEC-review tiền-hmw (PE xoá phiếu ở màn duyệt + lệnh Update workflow) — PASS-WITH-FLAGS 4H/8M/5L; spec trích-dẫn SẠCH nhưng 4 lỗ chí-mạng: 🔴 H1 class MỚI nới-authz-mà-không-ai-có-quyền — spec gắn [Authorize(Policy="PurchaseEvaluations.Delete")] lên endpoint đang KHÔNG có policy; sqlcmd Dev đo: CanDelete=1 chỉ Admin+DeptManager, 11/13 role = 0 (DbInitializer.cs:2515 canDelete = roleName==DeptManager, seeder-2 chỉ nâng Read/Create + skip-if-exists ⇒ prod không tự vá) ⇒ vừa regression (Drafter mất xoá-nháp đang chạy) vừa feature chết (Procurement 403). MenuPermissionHandler.cs:41-51 khớp MenuKey CHÍNH XÁC, 0 kế-thừa — inheritance của GetMyMenuTreeQuery chỉ là display. LUẬT: đóng API = phải đo bảng Permissions xem AI còn qua được; test-403 một-chiều luôn xanh-giả. · H3 IgnoreQueryFilters() gỡ filter chứ không đảo ⇒ list "Đã xoá" thiếu .Where(IsDeleted) + thiếu tái-lập IDOR :596-617 = lộ toàn hệ. · H2 cờ trên ApprovalWorkflowLevel = 1 row = 1 NGƯỜI, repo có SẴN 2 idiom cho cờ anh-em F5 (Service:859 per-row ⟂ Features:1182 g.Any() per-Cấp) ⇒ "per-Cấp" trong spec = N người xoá được (owner muốn 1). · H4 lệnh Update workflow không khai policy mà chính nó là cổng cấp quyền (thêm-người + bật-cờ). · M1 phản-ví-dụ cho luật "AN TOÀN ⟺ giữ 2 tập Order": cờ AllowApproverFinalize đổi ĐIỂM KẾT THÚC phiếu đang chờ (:859-878) · pendingLevelGroup.First() (:733-734, tie không có tie-breaker) → thêm/bớt row cùng Order đổi slot chữ-ký Admin · thêm người vào Cấp ĐÃ QUA → ComputeLevelStatus thuần-con-trỏ (:1135-1148) hiện "Done" dù chưa ký. ⇒ con-trỏ-không-dịch ≠ phiếu-không-hỏng. · M3 soft-delete ⇒ cascade không chạy ⇒ LevelOpinion mồ-côi vẫn Restrict Level ⇒ nợ hoãn (N1) ăn thẳng vào luật mới F-5 cùng spec. · M4 phiếu ChoDuyet chỉ vào 2/4 phép cộng ⇒ test "cả 4 giảm" bất-khả-xanh. · M6 thêm key Pe_* KHÔNG đổi Policies/Menu keys (derived từ MenuKeys.All, Pe_* sinh factory) ⇒ spec bảo sửa số canonical = hỏng detector. Cách phá F.0 (6 đường, tắc cả 6) ⇒ mệnh-đề trung-tâm ĐỨNG, chỉ tiêu-đề rộng quá. Tag [s155, spec-review-pre-impl, authz-widen-nobody-has-it, ignorequeryfilters-not-inverted, order-set-rule-underfit]

  • [verbatim → git 8b6df0a closeout] S146 (07-22) PRE-COMMIT spec-v2-applied (governance 20 file) — 2 MAJOR THẬT (cả hai của LEAD); nấc verified tự-chạy-lệnh không-tin-lead: F1 session-end.md còn hook-3-path GẠCH-NỐI dù worker CE đã chỉ đích-danh (class "residual có người chỉ tận nơi vẫn rớt") + bất-đối-xứng nội-bộ (pause.md đã 4-path). F2 phép quét cardinality của lead siết LỆCH-TRỤC (co-occurrence CÙNG-DÒNG + 1 mẫu-chữ) → re-run HEAD tiền-vá lọt 4 ca thật gồm chính F1. F3 HELD (git show da7ee8a: hook 4-path + -File re-đọc mỗi Stop). 🔴 Bài rút: lead sửa 1 phép quét 4 lần/phiên vì mã-hoá ý-định NGỮ-NGHĨA vào regex; nấc đúng = lưới-soát-cho-người + allowlist CÓ TÊN + use⟂mention; lần-4 = citation-trap (dò bắt chính nốt-vá vì nó trích giá-trị cũ).

  • S147 (07-23) DIAGNOSIS-review PE attach TraLai (no diff — verify root-cause + stress fix) — Diagnosis PASS 5/5, fix CORE-safe/EXT-unsafe: 5 claims verified from disk; BE-no-guard CONFIRMED intentional by S78 changelog L9 ("handler KHÔNG guard drafter-only → approver upload no-403") + sole pipeline behavior=ValidationBehavior. 🔴 MAJOR blind-spot: attachEditable=isDrafter&&isEditablePhase SAFE for GeneralAttachmentsSection (:2013 readOnly=raw, no carve-out) but UNSAFE for SupplierAttachmentsCell (:2758) whose readOnly=itemsReadOnly (readOnly&&!approverEditMode, Mig28-F3 ChoDuyet approver-edit) → naive REPLACE breaks approver QuoteDocument edit in ChoDuyet; SAME gap in optional BE guard (carve-out {ChoDuyet+ApprovalAttachment} misses ChoDuyet+QuoteDocument). Scope trap: isDrafter@:140 in MAIN scope, OUT-of-scope at :2013/:2758 (child comps take only {ev,readOnly}); changing :421 over-broadly hits HoSoLinkRow:2017. Completeness: WORKSPACE (readOnly=false, picker editableOnly∋TraLai) already edits comparison-doc in TraLai → bug is LIST-detail-only (:574/:669 hardcode). LESSON: decouple a gate → trace if shared prop already carries a carve-out (itemsReadOnly ≠ raw readOnly); "same fix" for sibling surface may hit a DIFFERENT gate source.

S152 (2026-07-26) — D2 Fidelity-gate 6 gist "CỤM BỔ SUNG" (coverage-diff) — PASS_WITH_FIXES (A/B/C/D PASS · E FAIL)

  • Census thay spot: 307/307 trích có trong verbatim CẶP (275 exact + 32 sau khi hoàn '"), 307/307 chứa ĐÚNG token gắn nhãn, 307/307 token thật-sự VẮNG khỏi gist tiền-append (0 gap thổi-phồng). ref=46 khớp đúng claim lead. Trích = cửa-sổ ~150 ký-tự cố-định, token ở ~27% → cắt giữa từ ở 2 biên nhưng payload (file:line/finding) còn nguyên ⇒ điều-hướng được, KHÔNG rác.
  • 🔴 E FAIL — class-gap hệ-thống, chữ-ký sạch: máy-trích emit file-ref CHỈ cho {.cs 101/.tsx 45/.ts 16/.ps1 8} = 170 token, ZERO cho {.yml,.json,.slnx,.csproj,.sql,.config} ⇒ 13 token infra vắng ở 5/6 cặp. Nặng nhất: deploy.yml (chính file pipeline, trong gist của vai CI/CD!) · appsettings.Production.json (16 lần trong verbatim) · 2× s59-*.sql (chạy TAY prod ngoài pipeline) · memory-budget.json (single-source canonical CLAUDE.md). Header cụm TỰ đặt chuẩn "file-ref phải sống trong gist" mà KHÔNG khai N/A ⇒ trượt bằng chính thước mình.
  • 🔴 3 THƯỚC-HỎNG (bug ở phép đo, không ở vật): (1) md5 disk vs git show — spec gate ghi vậy — báo FAIL GIẢ 3/6 verbatim do worktree CRLF ⟂ blob LF (autocrlf=true + 188 file legacy i/lf w/crlf); đúng phải git diff HEAD --quiet hoặc strip-CR 2 phía. (2) grep -c distill-gen vô-dụng vì CHÍNH header cụm chứa chữ "distill-gen giữ" (citation-trap nhẹ) → phải so VALUE distill-gen:\s*\d+. (3) grep -iF trên MSYS trả 0-hit im-lặng cho pattern ASCII trong file UTF-8 (Mig42: -F=1 nhưng -iF=0) = bẫy vắng-mặt-trông-giống-sạch S146 — thoát nhờ đối-chiếu Python.
  • Tự bắt 2 lỗi của CHÍNH mình trước khi báo: "Mig 47/50/42/46 MISS" = artifact chuẩn-hoá của tao (Mig42 liền không dấu cách, có ĐỦ 2 phía) · context-regex .{70} trả RỖNG đọc nhầm thành sạch → phải .{0,70}. ⇒ LUẬT: mọi MISS phải literal-grep XÁC-NHẬN 2 phía bằng công-cụ THỨ HAI trước khi vào report.
  • D re-ground từ đĩa: docs/gotchas.md count=83/max=83 ⇒ 0 nhãn gotcha #N>83; soi NGƯỢC 24 dòng gotcha ≤83 tìm mirror-error (run-number đội lốt gotcha) → 0 ca, mọi #N đều là gotcha thật trong ngữ-cảnh nguồn. Tag [s152, d2-fidelity-gate, coverage-diff, extractor-ext-blindspot, thuoc-hong-x3]

@S159-curate — moved from L1 (S155-đợt2 verbatim, moved-not-cut)

  • S155-đợt2 (07-27) PE delete-approver DIFF-review #2 (12 FLAG 2H/4M/6L · ĐỪNG-DEPLOY): 🔴 class MỚI hợp-đồng-đứt-giữa-2-bờ — FE type chép tay khai allowApproverDelete: boolean, BE record chỉ 8-member KHÔNG có cờ ⇒ nút CHẾT mà tsc + dotnet build + 561-test đều XANH (mọi thước đo đo chỗ khác) ⇒ phép rẻ nhất = đếm member DTO vs khoá FE + grep -c <cờ> ở file dựng DTO. · policy-gate X.Delete chặn ĐÚNG nhóm cần dùng (đo DB: 11/13 vai CanDelete=0, 2 seeder KHÔNG BAO GIỜ nâng) ⇒ owner gỡ policy; verify "gỡ authz" = truy TỪNG dòng chặn thành bảng + grep .First() fallback + grep Admin trong chính file (gỡ policy sinh LOW mới: endpoint thành máy-dò 4-loại-phản-hồi cho mọi tài khoản). · mã ĐỔI giữa lượt soi ⇒ re-đo đĩa TRƯỚC verdict; test đổi chiều (==X==null) = ĐỔI-SPEC hợp lệ ≠ nới-assert vì 2 mệnh đề loại trừ nhau (nới = mệnh đề mới SUY RA được từ cũ). · cascade Add con → Remove cha → 1 SaveChanges: chứng "site duy nhất" bằng liệt-kê-vét-cạn 34 Remove → lọc 8 → xét cha-con từng cái. Tag [s155-dot2, hop-dong-dut-2-bo, policy-gate-do-DB, re-do-dia-truoc-verdict]

Moved @S160 (2026-07-29) — verbatim from L1 (moved-not-cut)

S149 (2026-07-24) — gate hội-tụ-bookend [LEAD GHI ON-BEHALF @S150 — M9/B3 theo H2-F4 (1 invocation thật → 0 entry); nguồn: runs/2026-07-24-S149-hoi-tu-bookend/sub-reviewer-hoi-tu.md 15.733B]

  • /fable-real reviewer gate spec hội-tụ-bookend: GO-WITH-FIXES 1C/6M/4m (CLEAN 218K, 0 garble) — spec v1→v2 trước wave implement 5-lane Opus (5/5 done 946K 0-garble). Lưu ý sổ: lượt gate adap-backlog wf_f4e4c006 KHÔNG tính invocation vai này (reviewer-lane skeleton-ruột-rỗng — khung 274B, 0 append, return+resume đều fail → em-main-solo re-do; xem sổ garble sub-class @S150).

@S161-curate (2026-07-29) — moved from L1 HOT (hook-cap 24.5KB > 17.1KB)

  • S159 (07-29) dashboard "toàn trình" đợt-4 FE-only (fe-user 984+/337, PWF 7 FLAG 0H/2M/5L): 🔴 tsc XANH đo ÍT hơn vẻ ngoàife-user/tsconfig*.json KHÔNG có strict/strictNullChecks (chỉ noUnusedLocals) ⇒ tra cờ tsconfig TRƯỚC khi trích tsc làm bằng chứng; ngược lại noUnusedLocals+pass = bằng chứng MẠNH HƠN grep cho claim "đã gỡ khối X" (compiler chặn nếu sót import). · class nhãn khẳng định chiều-ngược: dot-map none='chưa tới' — không-suy-diễn "đã xong" là đúng, nhưng "chưa tới" CŨNG là khẳng định ⇒ sai cho GĐ ĐỨNG TRƯỚC + sai khi contractId != null có sẵn trong payload. · pager tính data.page±1 (keepPreviousData ⇒ stale) thay vì state ⇒ double-click = no-op. · verify đích điều hướng phải đọc CẢ breakpoint trang đích (panel hidden lg:block ⇒ ngõ cụt mobile; trang đích tự có nhánh matchMedia mà caller mới không copy). · regression đo HEAD⟂work bằng grep -c từng token: count 5→2 mà KHÔNG mất nhãn (inline-prop → STAGES[i].title) ⇒ đếm lệch phải truy CẤU TRÚC trước khi kêu hồi quy. · tự tính lại 4 tỉ-số contrast + tra @theme mọi var(--color-*) (0 dòng --color-*: initial ⇒ nấc mặc định còn) — 3/3 số designer ĐÚNG. · lời khai sub-file "766→1.130 dòng" SAI (đĩa 1.413 = 766337+984). [→ runs/2026-07-29-S159-tong-quan-pipeline-menu/sub-reviewer-diff-dot4.md 28,5KB]

  • S159 (07-29) đợt-5 menu 6-leaf HĐ + endpoint /contracts/deleted (PWF 10 FLAG 0H/4M/6L): 🔴 con-số TRONG CHÚ THÍCH cũng là khẳng-định đo-được — diff SỬA comment D3 thành "NAY CÓ 2 chỗ IgnoreQueryFilters", grep -rn ra 3 file/17 site (ApprovalWorkflowV2AdminFeatures 15 site); tôi suýt duyệt bằng mắt ⇒ luật: comment mang số ⇒ chạy phép đếm, và số viết dưới dạng LUẬT ("chỗ duy nhất ⇒ CẤM…") sai thì lan sang người sửa sau. · class mirror-nửa-vời khai thừa phạm-vi: comment nói "Hộp thư + Tổng quan viết HOA" nhưng "Hộp thư" render bằng StaticLeaf KHÁC component ⇒ đọc comment ≠ đọc call-site. · cookie-cutter phải soi CẢ phần PE đã CHẶN: bản HĐ copy list-deleted nhưng bỏ disabled={deletedView} ⇒ click row → detail 404 → panel trắng (page thiếu nhánh isError) + mobile navigate ra trang 404. · mirror 2-app: fe-admin ẩn Ct_* (⇒ 21 leaf mới KHÔNG cần route) nhưng Khkk_* KHÔNG ẩn ⇒ thiếu 2 staticMap = drop silent #50 — kiểm hide-filter TRƯỚC khi kêu thiếu mirror. · tsc -p tsconfig.app.json EXIT=0 + noUnusedLocals = chứng cắt-hero-không-mồ-côi MẠNH HƠN grep (nhắc lại: fe-user KHÔNG bật strict). · ContractsMenuKeys.All ⇒ policy Contracts.Read có thật; MenuPermissionHandler khớp ĐÚNG-KHOÁ, KHÔNG kế thừa root (#82). [→ runs/2026-07-29-S159-tong-quan-pipeline-menu/sub-reviewer-diff-dot5.md]

  • S160 (07-29) reviewer CHỐT-CUỐI /fable-real (verify 13-fix landed) — #53 chết sau Trục-1+Trục-2, đĩa cứu: khuôn review-của-review: chấm "fix ĐÃ LAND + ĐÚNG codebase, không đẻ lỗi mới" — 12/13 landed-đúng + ~30 anchor re-verify THẬT @HEAD, 1 half-fix. Bài: (1) fix áp NỬA spec = dư-lượng thật — W7 §② sửa badge-nguồn nhưng bảng §① cùng file sót ⇒ soi CẢ FILE khi nhận "đã fix", không chỉ chỗ được trỏ (lớp vá-1-nửa-cùng-lớp S122); (2) anchor-label ⟂ thân — gate-5-anchor W3 vẫn liệt PEWS:1008 sau khi thân phán khuôn đó SAI ⇒ anchor-list là artifact riêng phải sync khi thân đổi; (3) anchor off-by-N — "2 checkbox :1267-1268" trúng 1 (SkipToFinal ở :1256) ⇒ dải anchor phải grep CẢ 2 symbol; (4) verify NGƯỢC premise clone: re-đo ContractWorkflowService.cs:191-198 admin-override-gán-qua-biến + ContractChangelogConfiguration:22-25 FK-Cascade + ContractAttachmentFeatures:56-152 0-IDOR — 3/3 premise HIGH clone ĐỨNG ⇒ clone-review có răng thật; (5) O-A moot-check: owner để-mở ⇒ F-C3/F-C5/F-S2-grant MOOT-đúng (không siết thì không grant), KHÔNG phải lead né. #53 lần 2/phiên trên reviewer — return "Trục-2: xác vị file…" (mẩu giữa việc) nhưng sub-file 8KB có Trục-1+Trục-2 đủ ⇒ lead finalize VERDICT+LỖI-MỚI+LEFTOVER on-behalf từ đĩa (0 mất kết-luận vì ghi-đĩa-trong-lúc-làm). Tag [s160, chot-cuoi-verify-fix-landed, half-fix-soi-ca-file, anchor-label-vs-than, verify-nguoc-premise-clone, o-a-moot-check, 53-doc-cuu]

  • S160 (07-29) review SPEC-BỘ dry-run KHKK→HĐ-cứng [engine /fable-clone 6 lane opus + /fable-real chốt fable; runs/2026-07-29-S160-khkk-dryrun-plan/review-synthesis-clone-s160.md]: 6 lane (anchor-A rỗng #StructuredOutput-fail nhưng ghi-đĩa-lượt-1-2 cứu · B/C/wave-logic/owner-consist/security). 5/5 verdict SUA-TRUOC-THI-CONG, hội tụ cao ⇒ lead-verify 5 claim load-bearing 5/5 CONFIRMED đĩa. Bài đắt: (1) review SPEC ≠ review CODE — bắt lỗ ở acceptance + default-lấn-quyền + hố-chưa-khai, KHÔNG chỉ anchor (anchor 24-28/28 đúng dòng nhưng spec vẫn hỏng cấu-trúc); (2) seeder-grant no-op = 403 giết-feature IM LẶNG — row Permission đã tồn tại CanRead-only ⇒ grant kiểu insert rơi skip-existing continue (DbInitializer.cs:2242-2245), phải UPGRADE-if-exists (SeedProcurementMasterAccessAsync:2367-2374); acceptance đếm ROW = 0-bit, phải đo CỜ CanCreate/CanUpdate; (3) owner-authority finding — lane owner-consistency bắt lead đặt default lấn đúng chỗ owner phán "để yên" (O-3 "hợp đồng cứ từ từ" + STATUS:13 tái-khẳng-định) ⇒ surface AskUser thay vì tự quyết → anh chọn O-A gỡ hẳn wave; (4) "204 KHÔNG 409" PASS SẴN = acceptance 0-bit nửa-vế vì nhánh trình không đọc workflow (ContractWorkflowService.cs:70-89) — vế răng = currentApprovalLevelOrder=1 phải chạy tới lượt DUYỆT; (5) FK-547 compiler-không-chặn: gọi LogWorkflowTransitionAsync(Guid contractId) với plan.Id = enum/Guid cast được nên build xanh, nổ runtime — dùng bảng changelog RIÊNG của module mới; (6) choke-point "DUY NHẤT" sai — admin-override gán Phase QUA BIẾN (:190-193) nên literal-grep miss (lớp #81), phải kê 2 write-path. anchor-B census tên-test: repo 0/460 tên thuần-Việt ⇒ khuôn = English-predicate (owner chốt đổi). Ensemble ĐÓNG GÓI C2 ăn: 6 lane ≤3-file + khung-rỗng-lượt-1-2 ⇒ 0 lane chết dù 1M+ token. Tag [s160, review-spec-bo, seeder-grant-no-op-403, acceptance-dem-row-0bit, owner-authority-surface, 204-khong-409-pass-san, fk-547-compiler-mien, choke-point-2-write-path, test-name-census-repo]

@S162-curate (2026-07-30) — moved verbatim từ L1 (hook 23.9KB > sàn 17.1KB)

  • S161-W2 (07-29) KHKK CRUD review — PWF 12 FLAG 3C/5M/4m [chết #53 sau Trục-4 (13.9KB ghi-từng-trục sống trọn) → lead đo Trục 5-7 + verdict on-behalf; 11 FIXED cùng lượt + 1 GIỮ]: 🔴 Trục-1 hợp-đồng FE↔BE VỠ 6 điểm khi 2 lane viết SONG SONG từ cùng spec — tsc+build+574-test đều XANH cả 6: route picker lệch tên (F-1, 404 đội lốt empty-state vì TanStack nuốt lỗi + ?? []) · body purchaseEvaluationId vs PeId (F-2 — D1 của BE lập luận "FE đọc cùng spec sẽ khớp" = GIẢ ĐỊNH, không phải phép đo; FE đã KHÔNG làm thế) · dossier body thiếu planId (F-3) · FE chỉ gọi POST khi BE ép Id=null ⇒ Sửa-đẻ-bản-sao im lặng (F-4) · peTenGoiThau (F-5) · winnerSupplierNames BE không có (F-6 — bị F-1 CHE: mảng rỗng nên .map chưa chạy, vá F-1 xong mới lòi = 2-lỗi-che-nhau). Luật rút: đối chiếu hợp-đồng = so ROUTE+FIELD từng cái giữa types-FE và record-BE trên ĐĨA, đừng tin lời khai lane nào. · F-8/F-9 security: list bịt mà detail/download 0-rào ⇒ rào list chỉ còn là UX — đối chứng twin PE :877-899 CÓ guard + S89 nháp-riêng-tư ⇒ thụt chuẩn, không phải "khuôn vốn thế" · F-12 INNER-join Projects (global-filter) = picker silent-vanish — lớp "vắng-mặt trông giống ổn". Trục-4 picker-khớp-rào ĐẠT (3/3 rào PE mirror đủ). Tag [s161-w2, hop-dong-2-lane-song-song-6-diem-dut, loi-khai-la-gia-dinh, 2-loi-che-nhau, list-bit-detail-mo-rao-thanh-ux, inner-join-global-filter-vanish]

  • S161 (07-29) W1 KHKK tiền-commit (Mig 69 + seeder + Designer type-10) — PWF 10 FLAG 1H/3M/4m/2L: 🔴 HIGH lại nằm ở git chứ không ở mã (S155 tái diễn): 2/3 file Mig 69 UNTRACKED ?? mà snapshot đã tracked-M ⇒ commit -a nạp model 7 bảng nhưng BỎ migration; build+566 test vẫn xanh ⇒ gate = git status --porcelain -- src tests | grep '^??' phải RỖNG ngay trước commit. · MAJOR bắt được nhờ đi NGƯỢC lời-khai FE: comment FE tự khai "nhãn lấy từ BE applicableTypeLabel" ⇒ đi kiểm bờ BE: AwLabels.Type chỉ 3 entry, GetValueOrDefault(type, type.ToString()) ⇒ UI hiện "ContractSigningPlan" tiếng Anh và useState(\Quy trình ${label}`)**GHI chuỗi Anh vào cột Name DB** — lớp *hợp-đồng-đứt-2-bờ*, tsc+build+test đều xanh. **Luật rút: câu comment dạng "bên kia lo" = ĐI ĐỌC BÊN KIA.** · seeder 5/5 PASS (call sau revoke:2109>:2096; revoker chỉ Hrm|Off|Personal⇒ không lật 2-chiều;TryGetValuetuple(RoleId,MenuKey)— khuôn 1-role sẽ ném dup-key, unique-indexPermissionConfiguration:26cứu) nhưng **acceptance "đo CỜ" chưa đo được ở đâu**: Dev DB **0 row**Khkk* cả MenuItems lẫn Permissions (menus 100 vs prod 142) ⇒ chưa nhánh nào từng chạy. · **grep-cùng-lớp bằng TOKEN-SONG-SINH** (VehicleBookingLevelOpinionsrepo-wide) mạnh hơn grep tên-mới: chứng 3/3 site đủ + 0 site thứ 4. · 2 chú thích cùng file nay SAI SỐ ("7 bảng"/"7 khối" → 8) + comment nguồnMenuKeys.cs:37"CỐ Ý NGOÀI All" nay sai + anchor(:614)trỏ dòng TRƯỚC-commit (đúng = :645) ⇒ **diff sửa mã phải sửa MỌI số/neo trong chú thích cùng file**. · STATUS.mdMenu keys 54/Policies 216không đổi dù |All|=55 ⇒ derived-drift. Tag[s161, high-o-git-khong-o-ma, hop-dong-dut-2-bo-nhan-BE, token-song-sinh-sweep, seeder-upgrade-if-exists, comment-mang-so-va-neo]`


@S165-curate (2026-07-31) — moved verbatim từ L1 (hook 22.6KB > sàn 17.1KB)

  • S164 (07-31) gate K1 danh mục SP-002 (ContractCatalogEntries, Mig 70) — PASS-WITH-FLAGS 9 finding/0 blocker kỹ-thuật: build 0W/0E + 597 test (45D+552I) tươi. Lane khai ĐÚNG 100% ở chỗ đo được: seed 86/86 parse-máy khớp transcribe từng dòng (chỉ 8 mismatch = đúng tập lane đã khai), phân bố 5/10/5/23/14/15/13/1, SHA-pair FE d71a9e3b… ×2 khớp claim. Bài thu:🔴 giá-trị lớn nhất KHÔNG nằm ở mã mà ở GATE QUY-TRÌNH: spec đặt PRE-gate owner (OG-6) + kế hoạch tách 2 commit (code trước, seed sau khi gật) — code đúng hết mà commit gộp là vượt quyền owner; seeder per-Code idempotent KHÔNG có nhánh update ⇒ gật muộn = phải UPDATE tay. ② 2 quyết-định hợp-lệ ghép lại đẻ ghost-wire: lead bắt key vào MenuKeys.All (để có menu row) + spec bắt controller mirror khuôn Roles="Admin" ⇒ 4 policy ContractCatalog.* sinh ra mà 0 endpoint tiêu thụ; ma trận CRUD chỉ điều-khiển HIỂN-THỊ, tick CanCreate vẫn 403 / bỏ tick CanRead vẫn GET được (lớp #82) — phải đo grep policy chứ đừng suy từ "key đã vào All". ③ default-lấn-ngữ-nghĩa: spec IncludeInactive? (mặc-định-LOẠI) → code IsActive? (mặc-định-GỒM) ⇒ cột "ẩn khỏi picker" chỉ ẩn nếu MỌI consumer nhớ truyền tham số. ④ drift DELTA đo được (All=56, policy=224) mà STATUS.md:6 chưa đổi ⇒ acceptance "khai cùng commit" chưa đóng. Tag [s164, gate-quy-trinh-owner, ghost-policy-2-quyet-dinh-hop-le, default-lan-ngu-nghia, seed-doc-may] Evidence: .claude/workflows/runs/2026-07-31-S164-4gd-khkk-fanout/sub-reviewer-gate-k1.md. ⚠️ Sổ này 18.8KB > 17.1KB — nợ curate lượt sau.

  • S162 (07-30) cây 4-folder GĐ (FE-only 2 app) — PASS-WITH-FLAGS 8 flag/0 blocker: 🔴 class im-lặng-về-độ-chính-xác-của-con-số — 3 ca cùng lớp 1 diff, tsc+build ×2 xanh: hook VỨT total khi pageSize:200 ⇒ không biết mình bị cắt, badge tụt không dấu vết · pe.ContractId = contracts[0].Id ⇒ phiếu liên-danh N HĐ chỉ nối 1 mà badge in như thật (tái phát cardinality S87/S88 — field làm KHOÁ-NỐI phải đi đọc WRITE-SITE của nó) · fallback ?? '(chưa cấp mã)' trộn 2 nguyên nhân ⇒ khẳng định SAI, không phải degrade. · #82 ngược chiều: FE gate OR nhiều menu-key nhưng MenuPermissionHandler.cs:40 khớp CHÍNH XÁC 1 key ⇒ OR làm gate LỎNG HƠN policy, tự chuốc 403; gate query = ĐÚNG key policy của endpoint. 2 endpoint cùng diff kết luận NGƯỢC nhau (/contracts [Authorize] trần ⇒ KHÔNG 403) ⇒ đo TỪNG cái. · Nhãn ✓ không có phép đo: rubric 'responsive ✓' mà harness grep 'grid-cols-[19rem'=0 hit ⇒ 2 trang lưới chưa từng render; đọc ^import của harness = cách rẻ nhất biết ảnh CHỨNG được gì. Tag [s162, im-lang-do-chinh-xac, total-bi-vut, contracts0-cardinality, or-key-long-hon-policy, nhan-tick-khong-phep-do] Evidence: .claude/workflows/runs/2026-07-30-S162-cay-4-folder-gd/sub-reviewer-1.md · lead áp 5/8 flag (F-1/3/4/6/7) + F-8 sửa memory designer TRƯỚC ship bfc7b79; F-2 (liên-danh N-HĐ) + F-5 (layout 19rem chưa render thật) = giới-hạn khai thẳng lên HANDOFF slot (56).

S159 (2026-07-29) — review diff tổng-quan pipeline (đợt-1, run tong-quan-pipeline-menu) [LEAD SEED ON-BEHALF @S164 — H2 P2 @S163; run bị owner chốt "bỏ mạch" @S163 nhưng lane review ĐÃ chạy thật, distill giữ bài]

  • {nấc: verified (lead đọc lại sub-file 16.761B) · evidence: runs/2026-07-29-S159-tong-quan-pipeline-menu/sub-reviewer-diff-tongquan.md}
  • 7 FLAG (2M+5L), 4 bài giữ: ① [M] a11y AA — 2-3 <button> TRÙNG tên đọc được "Chờ tôi duyệt" dẫn 3 đích khác (UserDashboardPage.tsx:449/:495/:538); ngữ-cảnh phân-biệt chỉ tồn tại THỊ GIÁC (<h3> không link chương-trình với nhóm nút) ⇒ spec AA = nợ thật không phải thẩm-mỹ. ② [M] lọt tiếng Anh: rút TOÀN BỘ chuỗi hiển-thị MỚI từ diff (git diff | grep '^+' | grep -oE '>..<|label=|title=') rồi soi từng chuỗi — ra đúng 2 ("Pipeline"…) = phương-pháp đo 100%-tiếng-Việt tái-dùng được. ③ [L] 2 khoá cache cho CÙNG resource (['pipeline-pe-inbox'] mới vs ['pe-inbox'] có sẵn cùng endpoint cùng params) ⇒ 2 bản cache độc-lập, 2 màn 2 ảnh-chụp khác thời-điểm — check "khoá mới không đè khoá cũ" PASS mà vẫn nợ nhất-quán: 2 câu hỏi KHÁC nhau. ④ [L] báo lỗi 2 lần cùng sự-cố.
  • Kỹ-thuật BÁC-claim giữ: "queryKey mới đè cache list" → BÁC bằng liệt-kê key thật 2 phía (không giao) — bác cũng phải có chứng.

@S166-curate — moved verbatim từ L1 (S164/S165 gate K3)

  • S164/S165 (07-31) gate K3 KHKK (8 wf nhóm + port level-finalize + gỡ khoá Designer) — PWF 8 finding/0 blocker: build 0W/0E · 614/0 (45D+569I) · npm ×2 sạch; 3/3 quyết-định lead ĐÚNG kỹ-thuật. Bài thu:🔴 tham-số-chết-vì-thiếu-tầng-UI — BE port opt-out applyLevelFinalize đủ 3 tầng + seed cờ finalize cho TP.CCM ở CẢ 8 wf, nhưng panel KHKK POST body literal đúng 2 field {action,comment} ⇒ luôn finalize ⇒ trạm CEO chết 8/8, mất đúng quyền owner vừa chốt. Bắt bằng đối-chứng khuôn-nguồn: PE panel useState(false) + luôn gửi tường minh ⇒ PE opt-IN, KHKK opt-OUT ⇒ "mirror khuôn PE" SAI ở chiều mặc-định. Luật: claim 'port khuôn X' phải đo TẦNG-CUỐI (ai GỬI tham số), đừng đếm tầng-BE.sweep 2-cờ bất-đối-xứng — FE gỡ khoá CẢ 2 ô, BE chỉ gỡ 1 ⇒ tick bị NUỐT IM LẶNG (chính class comment vừa xoá đã cảnh báo, đảo chiều); vá 1 cờ ⇒ grep cờ ANH-EM ở CẢ 2 bờ. ③ spec liệt SAI site (bảo gỡ PUT-Conflict) — bác bằng grep typeEnum trong thân handler = 0 hit ⇒ luật CHUNG mọi type; lead cãi spec ĐÚNG khi có phép đo. ④ suite flake 1/3 lượt ⇒ 'N/0 tươi' phải khai SỐ LƯỢT. ⑤ DELTA STATUS chưa khai — tái phát y hệt K1 cùng phiên. Tag [s165, tham-so-chet-thieu-tang-ui, doi-chung-khuon-nguon, sweep-2-co-bat-doi-xung, spec-liet-sai-site] Evidence: runs/2026-07-31-S164-4gd-khkk-fanout/sub-reviewer-gate-k3.md