Skip to content

feat(evidence): refuse untrusted payloads as estimator authority - #142

Draft
seonghobae wants to merge 1 commit into
mainfrom
agent/payload-semantics
Draft

feat(evidence): refuse untrusted payloads as estimator authority#142
seonghobae wants to merge 1 commit into
mainfrom
agent/payload-semantics

Conversation

@seonghobae

Copy link
Copy Markdown
Contributor

Untrusted documents, external metadata, serialized records, and LLM outputs cannot become estimator or posterior authority (ADR 0008/0014; AGENTS.md). An LLM output is not source evidence. Identity, size, and authorization bounds are not that scientific-role gate.

Complementary to #135 (payload_bound: identity/provenance/size/depth), #141 (intake_authorization: grant presence), and #140 (checkpoint_authority: checkpoint versus estimator). This crate owns scientific-role validation of untrusted payloads.

Local gates:

  • cargo test -p payload_semantics --offline --lib --tests GREEN after RED (package did not exist)
  • clippy -D warnings PASS
  • workspace contract PASS
  • docstring contract PASS
  • documentation validation PASS
  • lines 152/152; nightly-2026-08-01 branches 6/6

Does not allocate migration 0008. Does not recreate payload_bound, intake_authorization, or checkpoint_authority.

Keep this PR draft. Preferred merge remains #46 only when exact-head required Checks pass and a qualifying independent (non-Cursor/CodeRabbit) APPROVE exists. Do not empty-commit.

Documents, external metadata, serialized records, and LLM outputs stay
outside estimator and posterior authority until a scientific role
validates (ADR 0008/0014). An LLM output is not source evidence.
Identity, size, and authorization bounds are not that semantics gate.
Recovery is the computed share of recovered roles that match known
truth versus collapsing every payload to an estimator.
@coderabbitai

coderabbitai Bot commented Aug 17, 2026

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e2ec1f94-914e-4d7b-9d8a-45fc1f699c5c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant