Three issues from zhiwei's strategy report:
1. '37 reassess all timed out (subprocess 60s)': real cause is per-call LLM
latency exceeding the 60s per-subprocess limit during the key5-dead/
gateway-unstable window. NOT 'no concurrency control' as reported (60s
is per stock, not for the batch). Fixes: per-call timeout 60->240s
(LLM cold-start is 20-100s), and cap AUTO_REASSESS batch to 5 stocks
per run with remainder continuing next run (was unbounded serial calls
that also blew the 120s cron script window).
2. '15 stocks entry-zone center wrongly 97.0': quality gates had no
zone-sanity-vs-price check, so bad data (bad quote or LLM template
output) could be written freely. New GATE_ZONE_SANITY (CRITICAL):
zone center must be within 0.3x-3x of current price. Verified: rejects
the exact 97-center-vs-5.69-price corruption, passes legit zones.
3. 'reassess overwrites manual SQL fixes': true by design; with
GATE_ZONE_SANITY at write time, reassess can no longer overwrite good
values with garbage - invalid writes get rejected + flagged instead.