KB-139F

Dieu43 Template: red_zones RED_ZONES.md (static)

2 min read Revision 1
dieu43context-packphase4a-pre-d-primetask2
<!-- VOLATILE HEADER -->

generated_at: {{generated_at}} build_id: {{build_id}} git_commit: {{git_commit}} trigger_source: {{trigger_source}}

<!-- /VOLATILE HEADER -->

RED ZONES

Do Not Bypass

  • No built-in renderer fallback (Đ43 §6.X rev 4)
  • No case-dispatch per section (Đ43 §6.X rev 4)
  • No ALTER TABLE trực tiếp (HP NT4)
  • No manual INSERT/UPDATE vào kb_documents (HP S176 gateway)
  • No business logic trong Nuxt (HP NT10)
  • No GRANT SELECT từng table (Đ43 §6.X P10 rev 2)
  • No bind pattern vào WHEN trigger (Đ43 §6.X P11 rev 2)
  • directus warehouse: psql role directus — R/W context_pack_section_definitions, dot_*, normative_registry, birth_registry, system_issues, dot_config
  • incomex_metadata brain store: Agent Data FastAPI ONLY — POST /documents?upsert=true với X-API-Key
  • SQL executor runtime: role context_pack_readonly (READ ONLY TX + timeout 30s)

Enforcement Laws

  • HP v4.6.2 NT1-NT13
  • Đ43 v1.2 FINAL rev 5
  • Đ35 v5.1 (DOT registry contract)
  • Đ41 (VPS-as-SSOT atomic write)
  • Đ33 v2.0 §14+§15 (access control + CI hooks)

Recovery Path

  • Vi phạm phát hiện → DỪNG, báo Desktop
  • Fix luật/config/template/query trước
  • Re-run dot-context-pack-build + dot-context-pack-verify
  • Paste real verify output, không bịa