Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -61,6 +61,7 @@ boundaries above remain the target modular MSA architecture.
| `tepp_simulation` | known-truth temporal/event data generation |
| `validation_core` | RMSE, bias, coverage, graph, and Monte Carlo metrics |
| `tepp_api` | versioned DTO, schema, and export contracts |
| `copy_identity` | a template copy is not the source document and not a state transition |

No crate exposes placeholder production behavior in Task 1. This prevents an
empty façade from becoming a de facto public API before its invariants and tests
Expand Down
2 changes: 2 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,8 @@ All notable changes to TEPP are documented here. The format follows Keep a Chang

### Added

- `copy_identity` identity gate: a template or pasted copy cannot reuse the source document identity or become a state transition; recovered copy kinds match known truth at a higher computed rate than collapsing every copy to the source (ADR 0003).
- `persistence_postgres` retention/deletion/legal-hold (migration `0007`): policy rows, legal holds that block completed deletion, evidence tombstones without raw-source restore, analysis exclusion only for `logical_revocation`/`identity_tombstone` (not `cache_export_removal`), and deletion requests bound to the cited retention policy's tenant/class/purpose.
- `tepp_api` adaptive orchestration router (ADR 0010): versioned `direct`/`verify`/`committee`/`conductor`/`abstain` selection from CPU `f64` risk, ambiguity, evidence, and token-budget inputs; recorded stages, recursion, decomposition, access lists, and role-specific reasoning effort; fail-closed document-controlled policy/access/credentials; LLM plans remain proposals under deterministic statistical authority; comparable-budget ablation requires a direct baseline; credential-free contextual-orchestrator binding. Live NIM HTTP remains accepted-target.
- `tepp_api` purpose-bound provider-payload minimization: time-bounded `PurposeGrant` evaluation, fail-closed expired/not-yet-valid/inverted/cross-tenant/impossible-calendar denial, semantic UTC calendar validation, refusal to copy identity mappings into model-provider payloads or ordinary logs, preservation of opaque analytical identifiers and membership roles (no blanket PII mask), a separately authorized scientific re-identification path, and an internally bound FIPS 180-4 SHA-256 audit digest appended through `ReidentificationAuditSink` before disclosure.
- `persistence_postgres` backup/restore integrity: restored snapshots stay unusable until tenant, canonical `SHA-256`, knowledge-cutoff eligibility, temporal window order, and append-only triggers revalidate; SQL probes raise `restore integrity failed` (ADR 0013).
Expand Down
4 changes: 4 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 2 additions & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ members = [
"crates/tepp_simulation",
"crates/validation_core",
"crates/tepp_api",
"crates/copy_identity",
]
default-members = [
"crates/evidence_core",
Expand All @@ -23,6 +24,7 @@ default-members = [
"crates/tepp_simulation",
"crates/validation_core",
"crates/tepp_api",
"crates/copy_identity",
]

[workspace.package]
Expand Down
3 changes: 2 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implemented in Rust.
## Current implementation state

This branch establishes the Task 1 Rust workspace and quality-gate foundation.
The ten bounded crates compile independently but intentionally expose no
The eleven bounded crates compile independently but intentionally expose no
placeholder production APIs. Domain behavior begins in Task 2 with immutable
evidence identifiers and source records.

Expand All @@ -22,6 +22,7 @@ crates/corpus_split
crates/tepp_simulation
crates/validation_core
crates/tepp_api
crates/copy_identity
```

## Local verification
Expand Down
17 changes: 17 additions & 0 deletions crates/copy_identity/Cargo.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
[package]
name = "copy_identity"
description = "A template copy is not the source document and not a state transition."
version.workspace = true
edition.workspace = true
rust-version.workspace = true
license.workspace = true
authors.workspace = true
repository.workspace = true
homepage.workspace = true
readme.workspace = true
keywords.workspace = true
categories.workspace = true
publish = false

[lints]
workspace = true
53 changes: 53 additions & 0 deletions crates/copy_identity/src/error.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
//! Fail-closed copy-identity errors.

use std::fmt;

/// A fail-closed copy-identity error.
#[derive(Clone, Copy, Debug, Eq, PartialEq)]
#[non_exhaustive]
pub enum CopyIdentityError {
/// A template copy was treated as the source document identity.
CopyIsNotSourceIdentity,
/// A template copy was treated as a state transition.
CopyIsNotTransition,
/// A recovery slice was empty or length-mismatched.
InvalidCopyPayload,
}

impl fmt::Display for CopyIdentityError {
fn fmt(&self, formatter: &mut fmt::Formatter<'_>) -> fmt::Result {
let message = match self {
Self::CopyIsNotSourceIdentity => "a template copy is not the source document identity",
Self::CopyIsNotTransition => "a template copy is not a state transition",
Self::InvalidCopyPayload => "invalid copy-identity payload",
};
formatter.write_str(message)
}
}

impl std::error::Error for CopyIdentityError {}

#[cfg(test)]
mod tests {
use super::CopyIdentityError;

#[test]
fn error_messages_are_stable() {
for (error, message) in [
(
CopyIdentityError::CopyIsNotSourceIdentity,
"a template copy is not the source document identity",
),
(
CopyIdentityError::CopyIsNotTransition,
"a template copy is not a state transition",
),
(
CopyIdentityError::InvalidCopyPayload,
"invalid copy-identity payload",
),
] {
assert_eq!(error.to_string(), message);
}
}
}
127 changes: 127 additions & 0 deletions crates/copy_identity/src/kind.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,127 @@
//! Template-copy identity versus the copied source document.

use crate::CopyIdentityError;

/// Closed vocabulary of copy-related document identities.
#[derive(Clone, Copy, Debug, Eq, PartialEq)]
pub enum CopyKind {
/// A template or pasted copy of an earlier source.
TemplateCopy,
/// The earlier source document being copied.
SourceDocument,
}

impl CopyKind {
/// Return the stable wire kind name.
#[must_use]
pub const fn wire_name(self) -> &'static str {
match self {
Self::TemplateCopy => "template_copy_of",
Self::SourceDocument => "source_document",
}
}

/// Parse a stable wire kind name.
///
/// # Errors
///
/// Returns [`CopyIdentityError::InvalidCopyPayload`] for unrecognized names.
pub fn from_wire_name(name: &str) -> Result<Self, CopyIdentityError> {
match name {
"template_copy_of" => Ok(Self::TemplateCopy),
"source_document" => Ok(Self::SourceDocument),
_ => Err(CopyIdentityError::InvalidCopyPayload),
}
}
}

/// Refuse to treat a template copy as the source document identity.
///
/// # Errors
///
/// Returns [`CopyIdentityError::CopyIsNotSourceIdentity`] when `kind` is
/// [`CopyKind::TemplateCopy`].
pub fn refuse_copy_as_source_identity(kind: CopyKind) -> Result<(), CopyIdentityError> {
match kind {
CopyKind::TemplateCopy => Err(CopyIdentityError::CopyIsNotSourceIdentity),
CopyKind::SourceDocument => Ok(()),
}
}

/// Refuse to treat a template copy as a forward state transition.
///
/// # Errors
///
/// Returns [`CopyIdentityError::CopyIsNotTransition`] when `kind` is
/// [`CopyKind::TemplateCopy`].
pub fn refuse_copy_as_transition(kind: CopyKind) -> Result<(), CopyIdentityError> {
match kind {
CopyKind::TemplateCopy => Err(CopyIdentityError::CopyIsNotTransition),
CopyKind::SourceDocument => Ok(()),
}
}

/// Fraction of recovered copy kinds that match known truth.
///
/// # Errors
///
/// Returns [`CopyIdentityError::InvalidCopyPayload`] when either slice is empty
/// or the lengths differ.
pub fn identity_recovery_rate(
truth: &[CopyKind],
decided: &[CopyKind],
) -> Result<f64, CopyIdentityError> {
if truth.is_empty() || truth.len() != decided.len() {
return Err(CopyIdentityError::InvalidCopyPayload);
}
let mut matches = 0_u32;
for (truth_kind, decided_kind) in truth.iter().zip(decided) {
if truth_kind == decided_kind {
matches += 1;
}
}
Ok(f64::from(matches) / truth.len() as f64)
}

#[cfg(test)]
mod tests {
use super::{
CopyKind, identity_recovery_rate, refuse_copy_as_source_identity, refuse_copy_as_transition,
};
use crate::CopyIdentityError;

#[test]
fn local_branches_cover_kinds_payloads_and_wire_names() {
assert_eq!(
refuse_copy_as_source_identity(CopyKind::TemplateCopy),
Err(CopyIdentityError::CopyIsNotSourceIdentity)
);
assert_eq!(
refuse_copy_as_transition(CopyKind::TemplateCopy),
Err(CopyIdentityError::CopyIsNotTransition)
);
refuse_copy_as_source_identity(CopyKind::SourceDocument).expect("source");
refuse_copy_as_transition(CopyKind::SourceDocument).expect("source");
for kind in [CopyKind::TemplateCopy, CopyKind::SourceDocument] {
assert_eq!(
CopyKind::from_wire_name(kind.wire_name()).expect("round-trip"),
kind
);
}
assert_eq!(
CopyKind::from_wire_name("summarizes"),
Err(CopyIdentityError::InvalidCopyPayload)
);
let matched = identity_recovery_rate(&[CopyKind::TemplateCopy], &[CopyKind::TemplateCopy])
.expect("rate");
assert!((matched - 1.0).abs() < f64::EPSILON);
assert_eq!(
identity_recovery_rate(&[], &[]),
Err(CopyIdentityError::InvalidCopyPayload)
);
assert_eq!(
identity_recovery_rate(&[CopyKind::TemplateCopy], &[]),
Err(CopyIdentityError::InvalidCopyPayload)
);
}
}
22 changes: 22 additions & 0 deletions crates/copy_identity/src/lib.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
#![forbid(unsafe_code)]
#![deny(missing_docs)]
#![allow(clippy::cast_precision_loss)]
//! A template copy is not the source document and not a state transition.
//!
//! Copy variants keep a distinct identity for relation-aware splits. They
//! never become input-process-outcome edges and never reuse the source
//! identity (ADR 0003).

mod error;
mod kind;

/// Fail-closed copy-identity errors.
pub use error::CopyIdentityError;
/// Closed vocabulary of copy-related document identities.
pub use kind::CopyKind;
/// Fraction of recovered copy kinds that match known truth.
pub use kind::identity_recovery_rate;
/// Refuse to treat a template copy as the source document identity.
pub use kind::refuse_copy_as_source_identity;
/// Refuse to treat a template copy as a forward state transition.
pub use kind::refuse_copy_as_transition;
67 changes: 67 additions & 0 deletions crates/copy_identity/tests/copy_identity_contract.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
//! A template copy is not the source document and not a state transition.

use copy_identity::{
CopyIdentityError, CopyKind, identity_recovery_rate, refuse_copy_as_source_identity,
refuse_copy_as_transition,
};

#[test]
fn a_copy_cannot_become_the_source_identity_or_a_transition() {
assert_eq!(
refuse_copy_as_source_identity(CopyKind::TemplateCopy),
Err(CopyIdentityError::CopyIsNotSourceIdentity)
);
assert_eq!(
refuse_copy_as_transition(CopyKind::TemplateCopy),
Err(CopyIdentityError::CopyIsNotTransition)
);
refuse_copy_as_source_identity(CopyKind::SourceDocument).expect("source");
refuse_copy_as_transition(CopyKind::SourceDocument).expect("source");
}

#[test]
fn recovered_kinds_match_known_truth_better_than_a_source_collapse() {
let truth = [
CopyKind::TemplateCopy,
CopyKind::SourceDocument,
CopyKind::TemplateCopy,
];
let recovered = truth;
let collapsed = [
CopyKind::SourceDocument,
CopyKind::SourceDocument,
CopyKind::SourceDocument,
];
let recovered_rate = identity_recovery_rate(&truth, &recovered).expect("recovered");
let collapsed_rate = identity_recovery_rate(&truth, &collapsed).expect("collapsed");
let expected = {
let mut matches = 0_u32;
for (truth_kind, decided_kind) in truth.iter().zip(recovered.iter()) {
if truth_kind == decided_kind {
matches += 1;
}
}
f64::from(matches) / f64::from(u32::try_from(truth.len()).expect("len"))
};
assert!((recovered_rate - expected).abs() < f64::EPSILON);
assert!(recovered_rate > collapsed_rate);
}

#[test]
fn empty_or_mismatched_kind_payloads_fail_closed() {
assert_eq!(
identity_recovery_rate(&[], &[]),
Err(CopyIdentityError::InvalidCopyPayload)
);
assert_eq!(
identity_recovery_rate(&[CopyKind::TemplateCopy], &[]),
Err(CopyIdentityError::InvalidCopyPayload)
);
assert_eq!(
identity_recovery_rate(
&[CopyKind::TemplateCopy, CopyKind::SourceDocument],
&[CopyKind::TemplateCopy]
),
Err(CopyIdentityError::InvalidCopyPayload)
);
}
7 changes: 7 additions & 0 deletions crates/copy_identity/tests/crate_contract.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
//! Integration contract for the `copy_identity` package identity.

#[test]
fn package_identity_is_stable() {
let observed = std::hint::black_box(env!("CARGO_PKG_NAME"));
assert_eq!(observed, "copy_identity");
}
2 changes: 1 addition & 1 deletion docs/TRACEABILITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ The full APA 7th standards/literature register remains `docs/research/standards-
| Rust workspace/quality foundation | ADR 0007 | workspace/CI/repository contract | implemented-main |
| six distinct clocks and uncertain intervals | PRD; ADR 0002 | PR #8 `temporal_core` on protected main; PR #5 historical only | implemented-main |
| Allen relation algebra/bounded closure | ADR 0002; temporal research | PR #9 `temporal_core` path-consistency on protected main | implemented-main |
| forward-only transition subgraph | PRD; ADR 0002/0003 | `relation_graph` on protected main | implemented-main |
| forward-only transition subgraph | PRD; ADR 0002/0003 | `relation_graph` on protected main; `copy_identity` copy-versus-source identity on the active PR | partial |
| event ontology/evidence mentions | PRD; ADR 0003 | `event_core` mention/instance separation on protected main; `persistence_postgres` mention SQL implemented-main refuses mention-as-instance; event-instance SQL (#39 implemented-main) refuses inverted windows; full intelligence stack remaining | partial |
| time-varying cross-classified multiple membership | PRD; ADR 0003 | `membership_core` network on protected main; multilevel estimators remaining | partial |
| leakage-safe availability/cutoff snapshots | PRD; ADR 0002/0013 | `corpus_split` on protected main | implemented-main |
Expand Down
2 changes: 1 addition & 1 deletion docs/adr/0003-relational-event-multiple-membership.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# ADR 0003 — Relational event ontology and time-varying multiple membership

**Decision status:** Accepted
**Implementation maturity:** partial — membership network and event mention/instance separation implemented-main; typed relation graph with forward-only transitions active-PR; multilevel estimators and persistence remain accepted-target
**Implementation maturity:** partial — membership network and event mention/instance separation implemented-main; copy-versus-source identity in `copy_identity` on the active PR; typed relation graph with forward-only transitions active-PR; multilevel estimators and persistence remain accepted-target
**Date:** 2026-08-05
**Supersedes:** None. ADR 0016 owns TDT/CHRONOS event-intelligence task semantics; this ADR remains authoritative for ontology, relation, role, and membership structure.

Expand Down
2 changes: 1 addition & 1 deletion docs/adr/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ Read [`ADR_POLICY.md`](ADR_POLICY.md) first. **Decision status and implementatio
|---|---|---|---|---|
| [0001](0001-rust-first-modular-msa.md) | Rust-first numerical core and CPU `f64` reference | Accepted | partial | ADR 0011 owns cross-service/MSA authority; 0001 retains numerical/backend authority. |
| [0002](0002-six-clock-temporal-semantics.md) | Six-clock temporal semantics and fail-closed historical leakage prevention | Accepted | active-PR | Unmerged PR #8 is the canonical Task 3 replacement implementing typed clocks/intervals against the current protected-main lineage; conflicted PR #5 is superseded lineage. Later graph/split enforcement remains target work. |
| [0003](0003-relational-event-multiple-membership.md) | Relational event ontology and time-varying cross-classified multiple membership | Accepted | partial | Weighted time-varying membership network/roles are active-PR (PR #12); full multilevel estimators, graph ontology, and persistence remain accepted-target. ADR 0016 owns event-intelligence tasks. |
| [0003](0003-relational-event-multiple-membership.md) | Relational event ontology and time-varying cross-classified multiple membership | Accepted | partial | Weighted time-varying membership network/roles are implemented-main (PR #12); copy-versus-source identity is `copy_identity` on the active PR; full multilevel estimators and persistence remain accepted-target. ADR 0016 owns event-intelligence tasks. |
| [0004](0004-shared-multilingual-latent-space.md) | One shared multilingual latent space with explicit invariance status | Accepted | accepted-target | ADR 0012 owns the full topic-estimator/backend/global-topic contract. |
| [0005](0005-posterior-esem-dsem.md) | Posterior-aware ESEM/DSEM and valid compositional coordinates | Accepted | accepted-target | Downstream psychometric authority; upstream topic/network model is clarified by ADR 0012. |
| [0006](0006-vram-gpu-nvidia-orchestration.md) | VRAM-adaptive GPU compute and model-credential boundary | Accepted | accepted-target | LLM orchestration policy superseded by ADR 0010; autonomous development authority governed by ADR 0015. |
Expand Down
Loading
Loading