Files
solution-erp/.claude/agent-memory/reviewer/MEMORY.md

21 KiB
Raw Blame History

Reviewer Agent — Persistent Memory

Persistent diary cross-session. Auto-injected first ~200 lines at spawn (L1 HOT). Update BEFORE every stop. Tiered Memory v1: L1 HOT soft-cap ~30KB · L2 archive/ on-demand · L3 RAG search_memory just-in-time. Keep entry ≤ 1.5K chars (gotcha #53). Full verbatim history pre-S40 → git d2f52ba + archive/2026-05-q1..q2.md; S51→S76 detail → archive/2026-06.md (S69/S70/S71/S80 curate). Archive map: archive/_INDEX.md + per-period .gist.md.

📁 Area memory (L2 on-demand — Read khi review vùng tương ứng)

  • S62 PE budget soft-warning — PASS: hard-block→soft-warning; submit-guard intact + validator giữ BudgetPeriodAmount>0, row8 negative-safe (additive-only). Validator class PurchaseEvaluationFeatures.cs:317.
  • Wire/mirror claim verification anchors — sha256 twin-file · git diff -U0 isolate true-adds · allowNegative bleed check · guard-still-intact grep.
  • S89 PE budget-sectionB review — investigator 3/3 upheld (do-not-touch FROZEN) + CAUGHT MISSED #70 race: Block B PRO row3/row8 share adjustMut + cross-echo ev stale + NO ||peFetching (every other cell gated). authz-lens ≠ concurrency-lens.
  • S89 PE ends-before-CEO PLAN review — CONCERN: BE 3-field design sound (Mig 58 col committed, no mig) but FE coverage gap — 4 PeUrgentChips render-sites, plan covered only 2 (missed InboxPage:290 despite BE Inbox A2 updated + wrong ListPage dir path).
  • S89 finalize-note PLAN review — CONCERN: plan ground-truth 100% accurate (all file:line verified incl self-flagged); gaps = note doesn't say intermediate approvers still sign + skipToFinal-last-level corner + Dev DB 9 migs behind.
  • S101 H18 WF2 governance re-run (self=workflow-lane · em-main synthesized): re-verified S100 Harness-18 adopt (5ee32c0, governance-only) — original WF2 wf_31ea3985-92c lost to CLI-restart → fresh wf_955643c3-f7d PASS_WITH_CONCERNS. Lane-A detector-teeth PASS (fault-inject 4/4 -RepoRoot temp-tree — proved detector FLAGS injected-stale, not happy-path). Lane-B caught 1 CONCERN em-main missed in S100 sweep: workflows/README.md:51 stale label "ledger orphan-scan" (NO _ledger token → grep-exact sweep skipped) → FIXED S101. Lesson: exact-token sweep misses paraphrased labels — widen to concept-phrase when retiring a named artifact. Lane-C #53 return-garble (workflow-lane returned no StructuredOutput) → recovered first-hand, NOT re-spawned (feedback_agent_return_garble_recover).
  • S103 H20+crystallized-backfill review — WF2 PASS (Lane-B gov-fidelity + Lane-C already-met/no-overclaim, fable-clone ensemble). 6/6 hashes recompute MATCH; 4 already-met VERIFIED file:line (detectors 4-layer C2 if n≠canon:247 · archive-gate value_protect ADVISORY:55-56 · C launcher n/a hmw.js:4-5 · F3 BƯỚC0.6 reads env-runtime:37); all no-overclaim danger-phrases NEGATED-context; applied-eval 4-caveat + selftest exit-0 fault-inject teeth; crystallized-backfill DRY target=0=OFF. 2 NIT: script echoes bare headroom w/o partial-floor-axis caveat (doc-layer+wire DO carry UPPER-BOUND) · guide-doc Opus-4.7 examples out of §L.D n=1 scope. Lesson: multi-axis warning (F4=token-undercount + partial-source-list) must appear in the SCRIPT's own output, not only the doc — reader runs script inline.
  • S101 H19 WF2 review LANE-C (adap-reports + honesty · self=reviewer · wf_5f308fd8-744=WF1): PASS. 4 adap-reports (H19 fable-clone + 3 model-tier) + send-email 6c. Hashes recompute indep MATCH (H19 6909299a + model-tier ee00d253/a7ff304b/eed277f7), all carry reviewer_gate: PASS. 12/12 honest; Q2 hysteresis 0.85/5/2 verbatim budget.json:35-37. Danger-phrase "verified" only in G-011 legend + "verified-pending-restart"; nấc="designed+will-dogfood, thật-mode CHƯA chạy". Lesson: hex→SHA disambiguation — recompute BOTH strip/no-strip variants to prove a hex string is a content_sha256 BODY-hash not a commit-SHA (line-29 5f511fe5→5f8b8504 = hash-transition, git cat-file=not-commits, claim TRUE presentation-nit only).

🎯 Role baseline

Adversarial pre-commit reviewer SOLUTION_ERP. Read-only verify + live curl prod UAT (*.solutions.com.vn). Tools: Read, Grep, Glob, Bash (curl + git diff + sqlcmd read) + 5 RAG MCP. Skills: dependency-audit-erp + contract-workflow + permission-matrix. Output: PASS/FAIL + concrete issues file:line. NEVER write code.


🚨 Recurring bug patterns (catch priority)

  • #44 Silent 403 class-level Authorize quá strict — Drafter dropdown empty silent (TanStack catch silent → UI empty). Grep \[Authorize\(Policy=.*\)\] class-level + curl non-admin expect 200. Fix: class-level [Authorize] only (any authenticated); POST/PUT/DELETE giữ [Authorize(Policy="X.Create")].
  • #43 Step.Order ≠ index 0-basedWhere(s=>s.Order==i) wrong row. Fix: EF query → in-memory OrderBy(Order).ToList() → index.
  • #42 Dual schema V1/V2 — Service phải branchif (entity.ApprovalWorkflowId is Guid awId) ApproveV2Async else V1Legacy.
  • Wire BE claim — grep diff // Mock/alert(/no POST-PUT-DELETE call + live curl expect 2XX. Severity CRITICAL block.
  • #70 FE absolute-set stale-echo race — N fields cùng-cột share 1 mutation + echo sibling từ server-snapshot (bs) + invalidate() fire-and-forget (không await) → lưu 2 ô liên-tiếp đè mất. Window mở SAU isPending=false (btn re-enable), KHÔNG lúc in-flight. Catch: đếm field-cùng-cột share mutation + check invalidate awaited; fix = useIsFetching gate nút Lưu tới khi refetch land.
  • #71 enum proxy-predicate pollution — thêm enum value vào entity dùng-chung → UI/guard phân-loại theo PROXY-predicate (supplierId===null) thay vì enum tường minh → value mới lẫn nhầm phân-loại + false-pass guard. Catch: grep mọi field-proxy predicate, loại value mới tường minh; build-verify TỪNG app.
  • Cross-module security mirror (S29 Smart Friend) — khi mirror entity/Command cross-module (PE→Contract→Budget V2), focus data-shape MISS security guard. Pattern: aw.ApplicableType == ExpectedType validate ON Create BEFORE instantiation (mirror PurchaseEvaluationFeatures.cs:62-77). Attack: Drafter forge POST với approvalWorkflowId của module khác → FK Restrict chỉ check Id-existence NOT ApplicableType → wrong-scope pin. Re-verify IsActive+IsUserSelectable server-side. Password ≥12 chars. Severity MAJOR.
  • #17 EF migration 3-filegit diff --name-only | grep Migrations/ expect 3 (target + Designer + Snapshot).

📋 6-category checklist (EVERY review)

  • Cat 1 Wire BE/feature claim: grep mock markers diff + await api\.(post|put|delete|patch)\( + live curl POST/PUT/DELETE if deploy claim + status matrix.
  • Cat 2 Schema integrity: 3-file rule Mig + column types vs entity def. Reference docs/gotchas.md (71 active).
  • Cat 3 Security: [Authorize] class-level ALL new controllers + per-action policy admin-scoped (gotcha #44) + FE PermissionGuard + menuKeys.ts mirror BE MenuKeys.cs + FluentValidation + EF parameterized.
  • Cat 4 Code quality: dotnet build SolutionErp.slnx 0 err + npm run build × 2 app (TS6 strict) + tests baseline 354 PASS (Phase 9 UAT exception OK) + no --no-verify + anti-fiddle (scope drift >20% LOC = FAIL) + mirror 2 FE app §3.9.
  • Cat 5 Test coverage: new helper → xUnit · new endpoint → integration · bug → regression test-before-fix. Phase 9 UAT test-after default OK (feedback_uat_skip_verify). Baseline 354.
  • Cat 6 Writing-quality (Harness-7, S64): outward text (verdict gửi anh / report) = tiếng Việt câu hoàn-chỉnh đủ dấu đúng ngữ-pháp; describe issue + acceptance criteria, NOT code edits. Escalate disagreement explicit.

⚠️ Anti-patterns + 🛡️ Smart Friend guard

  1. Recommend code edits (only describe issue+criteria) · 2. Skip live curl if deploy claim · 3. Accept "wire" without grep proof · 4. Defer to em main authority (escalate explicit) · 5. Skip MEMORY · 6. Lower bar match em main (Smart Friend Cognition anti-pattern).

Smart Friend (Cognition): NEVER lower bar. Em main code fine → PASS. Em main issues → FAIL with specifics regardless social pressure. "Quality ceiling set by primary, not escalation." Value = raise quality through catch.


🧠 SOLUTION_ERP review essentials (S80 verified — re-ground từ docs/STATUS.md canonical)

  • Tests baseline: 354 PASS (45 Domain + 309 Infra · 0 fail/skip). Must increase khi feature added (§7); Phase 9 UAT exception (feedback_uat_skip_verify).
  • Gotchas: 71 active (docs/gotchas.md, format ### N.). Latest: #69 bundle-hash non-determ (deploy rebuild-FE-uncond rotate) · #70 FE stale-echo race (useIsFetching gate) · #71 enum proxy-predicate pollution · #66 Tailwind v4 unlayered h1-h4 color thắng utility · #58 EF read-modify-write lost-update→ExecuteUpdate atomic.
  • Migrations: 57 latest AddPeSuggestedPriceNotes (path src/Backend/SolutionErp.Infrastructure/Persistence/Migrations/). PE-budget: Mig 50 PeWorkItemBudgets per-gói-thầu (DROP module Budget cũ) · Mig 54 giá-đề-xuất PRO/CCM + giá-chốt · Mig 55 CcmNote · Mig 56 ProInitial/ProAdjust split · Mig 57 ghi-chú-giá PRO/CCM.
  • Endpoints: ~253 · 88 SQL tables.
  • Identity password ≥12 chars (reject 11-char). Test creds: admin admin@solutions.com.vn/Admin@123456 (full) · UAT nv.test@solutions.com.vn/TestUser@123456 (Drafter CCM).
  • Prod: api/admin/eoffice.solutions.com.vn. Bundle live admin CsJetgZH / user BVS0ApIm (Run #330). Pin: MediatR 12.4.1 (flag Version="14) · Swashbuckle 6.9.0 · Node CI 20.x.
  • Conventions: docs/rules.md (§1.1 outward writing, §3.9 mirror 2 FE, §5.2 commit, §6.5 docs narrative, §7 test timing, §2.8 pin).

📅 Recent activity (compressed — full verbatim → archive/2026-06.md + archive/2026-07.md via archive/_INDEX.md)

  • S101 H19 fable-clone WF2 Lane-A (toggle mechanism) — PASS_WITH_CONCERNS (1 CONCERN, 0 BLOCKING): 3 Lane-A asks all CONFIRMED — (Q1) /fable-real=Write · /fable-clone=Remove-Item mirror ultra-on/off, both carry no-hot-reload warning; (Q2) semantic INVERSE (marker-absent=ảo-DEFAULT · present=thật) consistent across 8 statements + git check-ignore .claude/fable-real-mode.on=IGNORED (line 92 AFTER !.claude/** neg line 83, verified check-ignore -v) + tracked cmd-file NOT-ignored; (Q3) GAP-1 scope-guard "N lane CÙNG 1 vai, KHÔNG mixed-roster" pinned in BOTH cmd-files + §K.C, and hmw.js VALID_ROLES independently confirmed = all 9 roles no 2-position gate (resolveModel unrestricted) → GAP-1 leak framing ACCURATE not fabricated. CONCERN (refutation that landed): marker is a WRITE-ONLY dead artifact — /fable-real.md:10 claims "Mode persist qua marker → SỐNG qua session/compact" but NOTHING reads fable-real-mode.on; /session-start BƯỚC 0.5 reads only hmw-mode.on and was NOT extended (session-start.md unmodified in git status, empty grep for any reader). Write half-loop exists, read→report→route half-loop absent → wording overstates mechanism. Non-blocking because vacuously-met-today (all-inherit → 2 positions ALREADY top-model → 0 runtime-delta; toggle manual/owner-driven by design) — bites only when Fable returns + tiering resumes. Anti-pattern: mirror-a-toggle copies the WRITER side but silently drops the READER side — a persist-claim needs BOTH write-on-set AND read-on-session-start; verify the consumer exists, not just the producer. Vacuously-met disclosure itself was clean (§K.D + mark both say "KHÔNG overclaim runtime-delta"). (dời từ Role-baseline @S102 — H2 Placement-flag; NOTE @S102: reader BƯỚC 0.5b ĐÃ wire tại S101-cuối → CONCERN closed, marker có consumer.)

  • S100 H18 WF2 synthesis + Lane-B — SYNTHESIS reviewer 2-lane JSON→overall PASS_WITH_CONCERNS (LaneA PASS + LaneB PWC, neither BLOCKING). Re-verified indep: ledger +2/0-del revert-clean · ratio-band replaced |diff|>=10 · glob replaced 3-fixed-list · 6/6 consumers 🧊-marked · every LIVE _ledger marked (unmarked=history) · CONCERN workflows/README:51 no-token points-authoritative=non-block · KEY anti-pattern HELD (stale WF2 wf_31ea3985 NOT stamped, both placeholders await fresh run). Prior S100-bis Lane-B PASS (2 minor) folded in.

  • S98 (2026-07-02) 3 verify-lane (fidelity-gist impl-fe + cicd L1-curate + mega-line re-tier) — all PASS (minor only): Lessons: fidelity-gate 3-lớp = verbatim + pointer-arithmetic + ground-truth-code cho MỌI diễn-giải vượt-verbatim (honest-empty > bịa filler) · Windows byte-verify GROUND-TRUTH = .NET ReadAllBytes/wc -c/od -c (MSYS grep/sed strip \r báo sai) · conservation-proof = arithmetic full-accounting > spot-check; Read-tool truncate >2K → PS ReadAllLines+ordinal IndexOf. Detail → archive/2026-07.md (recovered S102 — cut-not-moved f229b07).

  • S97/S97-bis (2026-07-01) PE finalize UAT ×2 app + EndsBeforeCeo CONFIG→RUNTIME Mig 60/61 (anh Kiệt FDC) — PASS (0 issue): default-flip opt-out→opt-in byte-mirror SHA256 ×2; RUNTIME-flag set DUY-NHẤT 1/5 DaDuyet-nhánh (grep-all) + 4-projection nhất-quán + Mig 3-file OK + backfill-LIKE VN-chuỗi = false-pos MINOR-only; EF-ternary List/Inbox CONFIRMED-runtime via test-in-395. Detail → archive/2026-07.md (recovered S102 — cut-not-moved f229b07).

  • 2026-06-29 S93 Harness-16 MFE adoption review (WF2 wf_13e3d35a 3-lane PASS 0-blocking): code-gate re-derived denom-29 + leading-verb-trap DEFEATED (NEVER commit push→0 content-word) + READ-ONLY-budget proof (1 write-op .mfe-state.json); WF1-reviewer caught BLOCKING vocab-fork (memory-fidelity H6.7≠H16 → MFE+alias-map §H). Detail → adap-report harness-16-mfe. → _INDEX.

  • S92 (2026-06-29) Adversarial PROD-security hide 5 menu-groups admin-only on eoffice (uncommitted) — PASS (0 blocking, 1 awareness note): A-E all upheld; CatalogManager Danh-mục access stripped (intended-by-spec, role assigned to 0 users post-S89, flag em-main only). Detail + per-attack file:line → project_s92_admin_only_modules_revoke.md.

  • S91 (2026-06-25) PE D2 create-contract 1→N multi-winner + winner-names (FROZEN, NOT-deployed) — PASS: fix for S89-bis dead-end; codegen mid-loop SaveChanges flushes ONLY seq-row (contract built LOCAL); GiaTri per-winner Quote-sum join PES.Id; positional DTO arg-order verified 3 sites; FE mirror byte-identical; 419 PASS. Detail → archive/2026-06.md.

  • S90 (2026-06-25) PE stability-fix batch D1 (5 chg+11 test, FROZEN) — PASS: Block B re-key SelectedSupplierId→IsWinner (single unchanged proven); CEO-notify SaveChanges (was Add-but-never-flush); HoSoLink null-safe+clear-via-empty option(b); #70 ||peFetching 2 PRO cells; 413 PASS. Detail → archive/2026-06.md.

  • S89-bis (2026-06-25) AREA-6 FE-consumers (PE FROZEN, investigator verify) — 4/4 confirm + 1 NEW miss: all 4 hold; NEW catch = create-contract joint-winner DEAD-END (FE shows button on some(isWinner) but BE hard-blocks SelectedSupplierId is null). Anti-pattern: single→multi conversion stops at detail-display layer. Detail → archive/2026-06.md.

  • S89 (2026-06-25) AREA-4 workflow-edit (PE FROZEN, investigator verify) — 3 confirm/1 do-not-touch: HoSoLink #73-class clear-on-partial-edit CONFIRMED + NEW 2nd destructive call-site (PeDetailTabs:817 InfoTab.save omits hoSoLink). Anti-pattern: echo-all-siblings convention rots when NEW absolute-set field added. Detail → archive/2026-06.md.

  • S86 (2026-06-24) PE Section B 3-cột Dự-án|PRO|CCM (Mig 59) — PASS: authz byte-mirror UpdatePeSuggestedPriceCcm (NotFound→Forbidden, fail-closed); FE canEditCcm KHỚP BIT-EXACT BE gate; submit-guard untouched (grep CcmBudgetPeriod in Services=ZERO); div-by-0 safe; 402 PASS. Detail → archive/2026-06.md.

  • S82 (2026-06-21) Harness-15-v2 adopt review (0 code) — 3/3 lane PASS: caught 3 MINOR. Memory-note: broadcasts/_index.md sha = notify self-declared content_sha256 frontmatter NOT recompute → don't flag index-vs-file mismatch before reading frontmatter. Stamped-mark mid-session edit OK if only refresh confirmed-decision What-cell.

  • S76 (2026-06-19) PE budget 3-cột Mig 56 + badge — PASS: MAJOR race fixed gotcha #70 (useIsFetching gate). Badge role-set MUST mirror gate bit-for-bit. SURPRISE: spec "KHÔNG migration" FALSE — đọc changed-set thật, đừng tin scope-framing em-main. → _INDEX S76.

  • S72 (2026-06-18) Mig 54 PE giá-đề-xuất + CCM-finalize OPT-IN — financial go-live PASS:* fail-closed guard throw BEFORE set Phase=DaDuyet; finalize-bypass = 3 orthogonal gate + server-recompute amount no-trust-client. → _INDEX S72*.

  • S71 (2026-06-18) Harness-10 run-trace — PASS/GAPS: "TRACKED" 2-level = check-ignore(eligible) vs git-ls-files(committed), model only post git add. → _INDEX S71*.

  • S69 (2026-06-17) Office re-skin + golive authz — PASS: re-skin proof = grep api-call+queryKey sorted -u byte-equal; public-grant = granted root NOT inherit-root (no sibling cascade); accent missing -800 stop = silent no-class Tailwind v4. → _INDEX S69*.

  • S65 (2026-06-16) public HRM Hồ sơ + PE mục E — PASS: upgrade-path MUST MUTATE row (if(!row.CanRead){...}) NOT skip-existing when prior revoke pre-set false (S58-class); menu-hide ≠ API-lock. → _INDEX S65*.

  • S88 (2026-06-25) Fidelity-gate L2 gist distill (test-specialist) — FAIL (1 fabrication-by-merge): gist gán "Mig 45" cho cluster span 2 episode khi chỉ 1 mang số đó (Master = Mig 47). Anti-pattern: merge-distill fabricates false specificity; token-PRESENCE pass BLIND to cross-episode mis-attribution → QUALITY gate after presence gate. Detail → archive/2026-06.md.

  • 2026-07-10 (S108 first-real-run H19) [engine: fable-real-single · Fable-S108] (em-main harvest B3, GAP-2/3): Task single-deep-pass adversarial 3 artifact S108 (runbook 58.7KB + adap-request + email outward — $outwardFlag=Y Cat-6). Verdict FAIL — 1 CRITICAL (email claim “đã sửa comment” khi hmw.js:31-32 chưa sửa, cat xác nhận) + 4 MAJOR (2 stale-outage-claim sót §3.5/§4.3 · clone-example thiếu tier:'opus' trái K.B/floor-2 khi Fable UP · AP-4 tự-toggle trái K.D-2 · drift-note 9-vai sai vs engine-10) + 6 minor; core JSON-shape/biến/checklist/GAP-guard SOUND (7 refutation: 5 đứng · 2 vỡ về phía artifact). Learned: doc assemble-từ-N-worker → grep stale-claim theo CLASS toàn file sau khi fix đại diện (header “đã sửa 6” ≠ sửa hết) · mọi outward-claim “đã sửa X” phải cat X trước gate. Surprise: đoạn drift-note (viết để cảnh báo drift) là chỗ duy nhất mô tả sai canonical. Em-main áp 37-fix + vá hmw.js thật → verdict-fixes closed cùng phiên. Return dòng-1 Verdict-header chuẩn, 0 garble.


🔄 Curate trigger

  • ~30KB → archive recent → L2 archive/<period>.md (byte-exact append) + _INDEX.md substring pointer. Stale >3mo → remove.

  • S102 recovery (em-main, 2026-07-06): H2 Fidelity-FLAG cut-not-moved ×5 tại f229b07 (S101 nén L1, digest claim "Detail → archive" nhưng verbatim chưa move — chỉ còn trong git) → recovered 5 entry (S97/S97-bis/S98×3, content-exact từ git show 5ee32c0) vào archive/2026-07.md MỚI + _INDEX.md +5 pointer (count=1 verified); 2 digest-pointer L1 re-point 2026-06→2026-07; dead-link :72 project_s100_h18_wf2_synthesis.md (chưa từng tồn tại) reformat bỏ link; entry H19 Lane-A dời Role-baseline→Recent + note CONCERN-closed (BƯỚC 0.5b reader đã wire). Lesson: L1-shrink kèm claim "Detail→archive" = BẮT BUỘC grep moved-not-cut TRƯỚC khi trust digest.
  • Last curate: 2026-06-20 S80 (em-main, archive-gate keep-floor-hit → manual) (45.2→~14KB): moved 13 recent entries S65→S76 (lines 64-82 byte-exact via sed) → archive/2026-06.md (32.7→70KB, +13 entries) + _INDEX.md +13 substring pointers (all verified count=1). KEPT foundation + 5 compressed recent-summaries; UPDATED stale essentials (130→354 test, 55→71 gotcha, Mig 40→57, 84→88 tables, ~211→~253 endpoints) + 5-cat→6-cat (Cat-6 writing-quality). gist NOT updated (em-main distill later).
  • Prev curate: 2026-06-18 S71 (36.7→24.2KB): moved 10 entries; KEPT foundation + newest cluster. Prev S70 (42.5→24.8KB): built _INDEX.md + .gist.md gen:1. Prev S40 (28.4→18KB).