Files
solution-erp/.claude/agent-memory/reviewer/MEMORY.md
pqhuy1987 e35066016f [CLAUDE] Docs: S101 check-email AI_INFRA + H19 fable-clone formal adopt + model-tier 12/12
- check-email batch13 ack (SE caught-up H-17, Fable-restore H-8 recognized) + re-stamp H10 body-hash 5f511fe5->5f8b8504 (no-strip->canonical) + frontier flag#2 RESOLVED (AI_INFRA re-stamped 8b6a8354=SE-computed)
- model-tier bundle 07-03: 12/12 (all-inherit form-valid; v2-pin-simple not-adopted) + Q1/Q2 documented + selftest-stamp -> send-email 6c
- H19 fable-clone FORMAL ADOPT + RC-stamp RC-pqhuy1987-03-07-2026-17-46-35: 2 command fable-real/fable-clone (that/ao toggle, semantic-inverse) + marker gitignored + engine SS-K (K.A-K.D + 3 floor-fidelity gap) + session-start BUOC 0.5b reader (WF2-Lane-A fix marker-write-only) + 4 adap-report
- 2-workflow Harness-9: WF1 wf_5f308fd8-744 SOUND_WITH_CONCERNS (lost-to-interruption->resume-cached) + WF2 wf_ed5b972f-a4d PASS_WITH_CONCERNS 0-BLOCKING
- mapping reviewer + investigator-codebase; VACUOUSLY-MET-honest (all-inherit->0 runtime-delta; value=future-proof-floor + anti-consensus-catch NOT cost; nac designed+will-dogfood)
- GAP-3 AS-10 fired LIVE (WF1+WF2 lanes auto-harvested agent-memory -> dogfood-validate convention-not-mechanism; harness-sanctioned, verified, KEPT)
- email AI_INFRA harness-19-adopt-plus-model-tier (selftest-stamp 6c PASS)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-03 18:22:28 +07:00

99 lines
19 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Reviewer Agent — Persistent Memory
> **Persistent diary cross-session.** Auto-injected first ~200 lines at spawn (L1 HOT).
> Update BEFORE every stop. Tiered Memory v1: L1 HOT soft-cap ~30KB · L2 `archive/` on-demand · L3 RAG `search_memory` just-in-time. Keep entry ≤ 1.5K chars (gotcha #53).
> Full verbatim history pre-S40 → git `d2f52ba` + `archive/2026-05-q1..q2.md`; S51→S76 detail → `archive/2026-06.md` (S69/S70/S71/**S80** curate). Archive map: `archive/_INDEX.md` + per-period `.gist.md`.
## 📁 Area memory (L2 on-demand — Read khi review vùng tương ứng)
- [S62 PE budget soft-warning](project_s62_pe_budget_soft_warning.md) — PASS: hard-block→soft-warning; submit-guard intact + validator giữ `BudgetPeriodAmount>0`, row8 negative-safe (additive-only). Validator class `PurchaseEvaluationFeatures.cs:317`.
- [Wire/mirror claim verification anchors](feedback_wire_claim_verification_anchors.md) — sha256 twin-file · `git diff -U0` isolate true-adds · `allowNegative` bleed check · guard-still-intact grep.
- [S89 PE budget-sectionB review](project_s89_pe_sectionb_review.md) — investigator 3/3 upheld (do-not-touch FROZEN) + CAUGHT MISSED #70 race: Block B PRO row3/row8 share adjustMut + cross-echo `ev` stale + NO `||peFetching` (every other cell gated). authz-lens ≠ concurrency-lens.
- [S89 PE ends-before-CEO PLAN review](project_s89_pe_endsbeforeceo_plan_review.md) — CONCERN: BE 3-field design sound (Mig 58 col committed, no mig) but FE coverage gap — 4 PeUrgentChips render-sites, plan covered only 2 (missed InboxPage:290 despite BE Inbox A2 updated + wrong ListPage dir path).
- [S89 finalize-note PLAN review](project_s89_finalize_note_plan_review.md) — CONCERN: plan ground-truth 100% accurate (all file:line verified incl self-flagged); gaps = note doesn't say intermediate approvers still sign + skipToFinal-last-level corner + Dev DB 9 migs behind.
- **S101 H18 WF2 governance re-run (self=workflow-lane · em-main synthesized):** re-verified S100 Harness-18 adopt (`5ee32c0`, governance-only) — original WF2 `wf_31ea3985-92c` lost to CLI-restart → fresh `wf_955643c3-f7d` **PASS_WITH_CONCERNS**. Lane-A detector-teeth PASS (fault-inject 4/4 `-RepoRoot` temp-tree — proved detector FLAGS injected-stale, not happy-path). Lane-B caught **1 CONCERN em-main missed in S100 sweep**: `workflows/README.md:51` stale label "ledger orphan-scan" (NO `_ledger` token → grep-exact sweep skipped) → FIXED S101. Lesson: **exact-token sweep misses paraphrased labels** — widen to concept-phrase when retiring a named artifact. Lane-C **#53 return-garble** (workflow-lane returned no StructuredOutput) → recovered first-hand, NOT re-spawned (`feedback_agent_return_garble_recover`).
- **S101 H19 WF2 review LANE-C (adap-reports + honesty · self=reviewer · `wf_5f308fd8-744`=WF1):** PASS. 4 adap-reports (H19 fable-clone + 3 model-tier: opus / checklist / v2-pin-simple) + send-email 6c selftest. **Hash re-computed indep (PS .NET UTF8, canonical split-3 + strip-1-newline):** H19=`6909299a…` MATCH · model-tier=`ee00d253/a7ff304b/eed277f7` all MATCH · **all 4 carry `reviewer_gate: PASS`**. Model-tier 12/12 honest: C1 11/11 frontmatter `inherit` · C3 gotcha `[1m]` = frontmatter-scoped 0 vs naive `grep -c` = 4 PROSE hits (README:9/12/16 upgrade-notes + database-agent:46 rule-line — verified NOT frontmatter). Q1 G-015=git-diff+folder-scan orphan (error-ledger AS-10) · **Q2 hysteresis `0.85/5/2` VERIFIED verbatim in memory-budget.json:35-37**. **KEY honesty-catch (resolved-benign):** model-tier line 29 "re-stamp H10 `5f511fe5``5f8b8504`" reads like commit-SHA pair — `git cat-file` = NOT commits; **but hash-recompute proves they are content_sha256 BODY-hashes** (5f511fe5=old-no-strip / 5f8b8504=canonical = current declared) → claim TRUE (`→`=hash-transition), only presentation-nit. **Anti-consensus dogfood** cites `commit f229b07` (run-folder ephemeral) — S101 WF2 Lane-B catch; honest framing = "ensemble-PATTERN proven" NOT "H19-toggle verified" (nấc="designed+will-dogfood", "thật-mode CHƯA chạy"). No overclaim: only "verified" hits = G-011 legend + "verified-pending-restart". §9 3-floor-points verbatim in RC-stamp + VACUOUSLY-MET-SE annotation present (value=future-proof+anti-consensus NOT cost). send-email 6c ABORT recompute-SAME-as-step-4 + ordered BEFORE step-7-log. Marker `fable-real-mode.on` gitignored ✓ / command-file tracked ✓. Lesson: **hex→SHA disambiguation — recompute BOTH strip/no-strip variants to prove a hex string is a body-hash not a commit-SHA when text is ambiguous.**
---
## 🎯 Role baseline
Adversarial pre-commit reviewer SOLUTION_ERP. Read-only verify + live curl prod UAT (`*.solutions.com.vn`). Tools: Read, Grep, Glob, Bash (curl + git diff + sqlcmd read) + 5 RAG MCP. Skills: `dependency-audit-erp` + `contract-workflow` + `permission-matrix`. Output: PASS/FAIL + concrete issues file:line. NEVER write code.
**S101 H19 fable-clone WF2 Lane-A (toggle mechanism) — PASS_WITH_CONCERNS (1 CONCERN, 0 BLOCKING):** 3 Lane-A asks all CONFIRMED — (Q1) `/fable-real`=Write · `/fable-clone`=Remove-Item mirror ultra-on/off, both carry no-hot-reload warning; (Q2) semantic INVERSE (marker-absent=ảo-DEFAULT · present=thật) consistent across 8 statements + `git check-ignore .claude/fable-real-mode.on`=IGNORED (line 92 AFTER `!.claude/**` neg line 83, verified `check-ignore -v`) + tracked cmd-file NOT-ignored; (Q3) GAP-1 scope-guard "N lane CÙNG 1 vai, KHÔNG mixed-roster" pinned in BOTH cmd-files + §K.C, and hmw.js VALID_ROLES independently confirmed = all 9 roles no 2-position gate (resolveModel unrestricted) → GAP-1 leak framing ACCURATE not fabricated. **CONCERN (refutation that landed):** marker is a WRITE-ONLY dead artifact — `/fable-real.md:10` claims "Mode persist qua marker → SỐNG qua session/compact" but NOTHING reads `fable-real-mode.on`; `/session-start` BƯỚC 0.5 reads only `hmw-mode.on` and was NOT extended (session-start.md unmodified in git status, empty grep for any reader). Write half-loop exists, read→report→route half-loop absent → wording overstates mechanism. Non-blocking because vacuously-met-today (all-inherit → 2 positions ALREADY top-model → 0 runtime-delta; toggle manual/owner-driven by design) — bites only when Fable returns + tiering resumes. **Anti-pattern: mirror-a-toggle copies the WRITER side but silently drops the READER side** — a persist-claim needs BOTH write-on-set AND read-on-session-start; verify the consumer exists, not just the producer. Vacuously-met disclosure itself was clean (§K.D + mark both say "KHÔNG overclaim runtime-delta").
---
## 🚨 Recurring bug patterns (catch priority)
- **#44 Silent 403 class-level Authorize quá strict** — Drafter dropdown empty silent (TanStack catch silent → UI empty). Grep `\[Authorize\(Policy=.*\)\]` class-level + curl non-admin expect 200. Fix: class-level `[Authorize]` only (any authenticated); POST/PUT/DELETE giữ `[Authorize(Policy="X.Create")]`.
- **#43 Step.Order ≠ index 0-based** — `Where(s=>s.Order==i)` wrong row. Fix: EF query → in-memory `OrderBy(Order).ToList()` → index.
- **#42 Dual schema V1/V2 — Service phải branch** — `if (entity.ApprovalWorkflowId is Guid awId) ApproveV2Async else V1Legacy`.
- **Wire BE claim** — grep diff `// Mock`/`alert(`/no POST-PUT-DELETE call + live curl expect 2XX. Severity CRITICAL block.
- **#70 FE absolute-set stale-echo race** — N fields cùng-cột share 1 mutation + echo sibling từ server-snapshot (`bs`) + `invalidate()` fire-and-forget (không await) → lưu 2 ô liên-tiếp đè mất. Window mở SAU `isPending=false` (btn re-enable), KHÔNG lúc in-flight. Catch: đếm field-cùng-cột share mutation + check invalidate awaited; fix = `useIsFetching` gate nút Lưu tới khi refetch land.
- **#71 enum proxy-predicate pollution** — thêm enum value vào entity dùng-chung → UI/guard phân-loại theo PROXY-predicate (`supplierId===null`) thay vì enum tường minh → value mới lẫn nhầm phân-loại + false-pass guard. Catch: grep mọi field-proxy predicate, loại value mới tường minh; build-verify TỪNG app.
- **Cross-module security mirror (S29 Smart Friend)** — khi mirror entity/Command cross-module (PE→Contract→Budget V2), focus data-shape MISS security guard. Pattern: `aw.ApplicableType == ExpectedType` validate ON Create BEFORE instantiation (mirror `PurchaseEvaluationFeatures.cs:62-77`). Attack: Drafter forge POST với `approvalWorkflowId` của module khác → FK Restrict chỉ check Id-existence NOT ApplicableType → wrong-scope pin. Re-verify `IsActive`+`IsUserSelectable` server-side. Password ≥12 chars. Severity MAJOR.
- **#17 EF migration 3-file** — `git diff --name-only | grep Migrations/` expect 3 (target + Designer + Snapshot).
---
## 📋 6-category checklist (EVERY review)
- **Cat 1 Wire BE/feature claim:** grep mock markers diff + `await api\.(post|put|delete|patch)\(` + live curl POST/PUT/DELETE if deploy claim + status matrix.
- **Cat 2 Schema integrity:** 3-file rule Mig + column types vs entity def. Reference `docs/gotchas.md` (71 active).
- **Cat 3 Security:** `[Authorize]` class-level ALL new controllers + per-action policy admin-scoped (gotcha #44) + FE PermissionGuard + menuKeys.ts mirror BE MenuKeys.cs + FluentValidation + EF parameterized.
- **Cat 4 Code quality:** `dotnet build SolutionErp.slnx` 0 err + `npm run build` × 2 app (TS6 strict) + tests baseline **354 PASS** (Phase 9 UAT exception OK) + no `--no-verify` + anti-fiddle (scope drift >20% LOC = FAIL) + mirror 2 FE app §3.9.
- **Cat 5 Test coverage:** new helper → xUnit · new endpoint → integration · bug → regression test-before-fix. Phase 9 UAT test-after default OK (`feedback_uat_skip_verify`). Baseline 354.
- **Cat 6 Writing-quality (Harness-7, S64):** outward text (verdict gửi anh / report) = tiếng Việt câu hoàn-chỉnh đủ dấu đúng ngữ-pháp; describe issue + acceptance criteria, NOT code edits. Escalate disagreement explicit.
---
## ⚠️ Anti-patterns + 🛡️ Smart Friend guard
1. ❌ Recommend code edits (only describe issue+criteria) · 2. ❌ Skip live curl if deploy claim · 3. ❌ Accept "wire" without grep proof · 4. ❌ Defer to em main authority (escalate explicit) · 5. ❌ Skip MEMORY · 6. ❌ **Lower bar match em main** (Smart Friend Cognition anti-pattern).
**Smart Friend (Cognition):** NEVER lower bar. Em main code fine → PASS. Em main issues → FAIL with specifics regardless social pressure. "Quality ceiling set by primary, not escalation." Value = raise quality through catch.
---
## 🧠 SOLUTION_ERP review essentials (S80 verified — re-ground từ docs/STATUS.md canonical)
- **Tests baseline:** **354 PASS** (45 Domain + 309 Infra · 0 fail/skip). Must increase khi feature added (§7); Phase 9 UAT exception (`feedback_uat_skip_verify`).
- **Gotchas:** **71 active** (`docs/gotchas.md`, format `### N.`). Latest: #69 bundle-hash non-determ (deploy rebuild-FE-uncond rotate) · #70 FE stale-echo race (useIsFetching gate) · #71 enum proxy-predicate pollution · #66 Tailwind v4 unlayered `h1-h4` color thắng utility · #58 EF read-modify-write lost-update→ExecuteUpdate atomic.
- **Migrations:** **57 latest `AddPeSuggestedPriceNotes`** (path `src/Backend/SolutionErp.Infrastructure/Persistence/Migrations/`). PE-budget: Mig 50 `PeWorkItemBudgets` per-gói-thầu (DROP module Budget cũ) · Mig 54 giá-đề-xuất PRO/CCM + giá-chốt · Mig 55 CcmNote · Mig 56 ProInitial/ProAdjust split · Mig 57 ghi-chú-giá PRO/CCM.
- **Endpoints:** ~253 · **88 SQL tables**.
- **Identity password ≥12 chars** (reject 11-char). Test creds: admin `admin@solutions.com.vn/Admin@123456` (full) · UAT `nv.test@solutions.com.vn/TestUser@123456` (Drafter CCM).
- **Prod:** api/admin/eoffice.solutions.com.vn. Bundle live admin `CsJetgZH` / user `BVS0ApIm` (Run #330). **Pin:** MediatR `12.4.1` (flag `Version="14`) · Swashbuckle `6.9.0` · Node CI `20.x`.
- **Conventions:** `docs/rules.md` (§1.1 outward writing, §3.9 mirror 2 FE, §5.2 commit, §6.5 docs narrative, §7 test timing, §2.8 pin).
---
## 📅 Recent activity (compressed — full verbatim → `archive/2026-06.md` via `archive/_INDEX.md`)
- [S100 H18 WF2 synthesis + Lane-B](project_s100_h18_wf2_synthesis.md) — SYNTHESIS reviewer 2-lane JSON→overall **PASS_WITH_CONCERNS** (LaneA PASS + LaneB PWC, neither BLOCKING). Re-verified indep: ledger +2/0-del revert-clean · ratio-band replaced `|diff|>=10` · glob replaced 3-fixed-list · 6/6 consumers 🧊-marked · every LIVE `_ledger` marked (unmarked=history) · CONCERN workflows/README:51 no-token points-authoritative=non-block · KEY anti-pattern HELD (stale WF2 `wf_31ea3985` NOT stamped, both placeholders await fresh run). Prior S100-bis Lane-B PASS (2 minor) folded in.
- **S98 (2026-07-02) 3 verify-lane (fidelity-gist impl-fe + cicd L1-curate + mega-line re-tier) — all PASS (minor only):** Lessons: fidelity-gate 3-lớp = verbatim + pointer-arithmetic + ground-truth-code cho MỌI diễn-giải vượt-verbatim (honest-empty > bịa filler) · Windows byte-verify GROUND-TRUTH = `.NET ReadAllBytes`/`wc -c`/`od -c` (MSYS grep/sed strip `\r` báo sai) · conservation-proof = arithmetic full-accounting > spot-check; Read-tool truncate >2K → PS ReadAllLines+ordinal IndexOf. Detail → `archive/2026-06.md`.
- **S97/S97-bis (2026-07-01) PE finalize UAT ×2 app + EndsBeforeCeo CONFIG→RUNTIME Mig 60/61 (anh Kiệt FDC) — PASS (0 issue):** default-flip opt-out→opt-in byte-mirror SHA256 ×2; RUNTIME-flag set DUY-NHẤT 1/5 DaDuyet-nhánh (grep-all) + 4-projection nhất-quán + Mig 3-file OK + backfill-LIKE VN-chuỗi = false-pos MINOR-only; EF-ternary List/Inbox CONFIRMED-runtime via test-in-395. Detail → `archive/2026-06.md`.
- **2026-06-29 S93 Harness-16 MFE adoption review (WF2 `wf_13e3d35a` 3-lane PASS 0-blocking):** ⭐ code-gate re-derived denom-29 + leading-verb-trap DEFEATED (`NEVER commit push`→0 content-word) + READ-ONLY-budget proof (1 write-op `.mfe-state.json`); WF1-reviewer caught BLOCKING vocab-fork (memory-fidelity H6.7≠H16 → MFE+alias-map §H). Detail → adap-report harness-16-mfe. → _INDEX.
- **S92 (2026-06-29) Adversarial PROD-security hide 5 menu-groups admin-only on eoffice (uncommitted) — PASS (0 blocking, 1 awareness note):** A-E all upheld; CatalogManager Danh-mục access stripped (intended-by-spec, role assigned to 0 users post-S89, flag em-main only). Detail + per-attack file:line → [project_s92_admin_only_modules_revoke.md](project_s92_admin_only_modules_revoke.md).
- **S91 (2026-06-25) PE D2 create-contract 1→N multi-winner + winner-names (FROZEN, NOT-deployed) — PASS:** fix for S89-bis dead-end; codegen mid-loop SaveChanges flushes ONLY seq-row (contract built LOCAL); GiaTri per-winner Quote-sum join PES.Id; positional DTO arg-order verified 3 sites; FE mirror byte-identical; 419 PASS. Detail → `archive/2026-06.md`.
- **S90 (2026-06-25) PE stability-fix batch D1 (5 chg+11 test, FROZEN) — PASS:** Block B re-key SelectedSupplierId→IsWinner (single unchanged proven); CEO-notify SaveChanges (was Add-but-never-flush); HoSoLink null-safe+clear-via-empty option(b); #70 ||peFetching 2 PRO cells; 413 PASS. Detail → `archive/2026-06.md`.
- **S89-bis (2026-06-25) AREA-6 FE-consumers (PE FROZEN, investigator verify) — 4/4 confirm + 1 NEW miss:** all 4 hold; NEW catch = create-contract joint-winner DEAD-END (FE shows button on `some(isWinner)` but BE hard-blocks `SelectedSupplierId is null`). Anti-pattern: single→multi conversion stops at detail-display layer. Detail → `archive/2026-06.md`.
- **S89 (2026-06-25) AREA-4 workflow-edit (PE FROZEN, investigator verify) — 3 confirm/1 do-not-touch:** HoSoLink #73-class clear-on-partial-edit CONFIRMED + NEW 2nd destructive call-site (PeDetailTabs:817 InfoTab.save omits hoSoLink). Anti-pattern: echo-all-siblings convention rots when NEW absolute-set field added. Detail → `archive/2026-06.md`.
- **S86 (2026-06-24) PE Section B 3-cột Dự-án|PRO|CCM (Mig 59) — PASS:** authz byte-mirror UpdatePeSuggestedPriceCcm (NotFound→Forbidden, fail-closed); FE `canEditCcm` KHỚP BIT-EXACT BE gate; submit-guard untouched (grep CcmBudgetPeriod in Services=ZERO); div-by-0 safe; 402 PASS. Detail → `archive/2026-06.md`.
- **S82 (2026-06-21) Harness-15-v2 adopt review (0 code) — 3/3 lane PASS:** caught 3 MINOR. Memory-note: `broadcasts/_index.md` sha = notify self-declared `content_sha256` frontmatter NOT recompute → don't flag index-vs-file mismatch before reading frontmatter. Stamped-mark mid-session edit OK if only refresh confirmed-decision What-cell.
- **S76 (2026-06-19) PE budget 3-cột Mig 56 + badge — PASS:** MAJOR race fixed gotcha #70 (useIsFetching gate). Badge role-set MUST mirror gate bit-for-bit. SURPRISE: spec "KHÔNG migration" FALSE — đọc changed-set thật, đừng tin scope-framing em-main. → _INDEX S76.
- **S72* (2026-06-18) Mig 54 PE giá-đề-xuất + CCM-finalize OPT-IN — financial go-live PASS:** fail-closed guard throw BEFORE set Phase=DaDuyet; finalize-bypass = 3 orthogonal gate + server-recompute amount no-trust-client. → _INDEX S72*.
- **S71 (2026-06-18) Harness-10 run-trace — PASS/GAPS:** "TRACKED" 2-level = check-ignore(eligible) vs git-ls-files(committed), model only post `git add`. → _INDEX S71*.
- **S69 (2026-06-17) Office re-skin + golive authz — PASS:** re-skin proof = grep api-call+queryKey sorted -u byte-equal; public-grant = granted root NOT inherit-root (no sibling cascade); accent missing -800 stop = silent no-class Tailwind v4. → _INDEX S69*.
- **S65 (2026-06-16) public HRM Hồ sơ + PE mục E — PASS:** upgrade-path MUST MUTATE row (`if(!row.CanRead){...}`) NOT skip-existing when prior revoke pre-set false (S58-class); menu-hide ≠ API-lock. → _INDEX S65*.
- **S88 (2026-06-25) Fidelity-gate L2 gist distill (test-specialist) — FAIL (1 fabrication-by-merge):** gist gán "Mig 45" cho cluster span 2 episode khi chỉ 1 mang số đó (Master = Mig 47). Anti-pattern: merge-distill fabricates false specificity; token-PRESENCE pass BLIND to cross-episode mis-attribution → QUALITY gate after presence gate. Detail → `archive/2026-06.md`.
---
## 🔄 Curate trigger
- >~30KB → archive recent → L2 `archive/<period>.md` (byte-exact append) + `_INDEX.md` substring pointer. Stale >3mo → remove.
- **Last curate: 2026-06-20 S80 (em-main, archive-gate keep-floor-hit → manual)** (45.2→~14KB): moved 13 recent entries S65→S76 (lines 64-82 byte-exact via `sed`) → `archive/2026-06.md` (32.7→70KB, +13 entries) + `_INDEX.md` +13 substring pointers (all verified count=1). KEPT foundation + 5 compressed recent-summaries; UPDATED stale essentials (130→354 test, 55→71 gotcha, Mig 40→57, 84→88 tables, ~211→~253 endpoints) + 5-cat→6-cat (Cat-6 writing-quality). gist NOT updated (em-main distill later).
- **Prev curate: 2026-06-18 S71** (36.7→24.2KB): moved 10 entries; KEPT foundation + newest cluster. **Prev S70** (42.5→24.8KB): built `_INDEX.md` + `.gist.md` gen:1. **Prev S40** (28.4→18KB).