Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -61,6 +61,7 @@ boundaries above remain the target modular MSA architecture.
| `tepp_simulation` | known-truth temporal/event data generation |
| `validation_core` | RMSE, bias, coverage, graph, and Monte Carlo metrics |
| `tepp_api` | versioned DTO, schema, and export contracts |
| `inferred_status` | inferred relations cannot be promoted to observed evidence or transitions |
| `support_edge` | support, contradiction, summary, and outcome_of edges are not state transitions |
| `system_clock` | system time cannot be replaced by event, assertion, document, available, or cutoff time |
| `event_clock` | event time cannot be replaced by assertion, system, document, or available time |
Expand Down
2 changes: 2 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,8 @@ All notable changes to TEPP are documented here. The format follows Keep a Chang

### Added

- `inferred_status` identity gate: inferred relations cannot be promoted to observed evidence or to state transitions; recovered observed/inferred labels match known truth at a higher computed rate than treating every status as observed (ADR 0003).
- `persistence_postgres` retention/deletion/legal-hold (migration `0007`): policy rows, legal holds that block completed deletion, evidence tombstones without raw-source restore, analysis exclusion only for `logical_revocation`/`identity_tombstone` (not `cache_export_removal`), and deletion requests bound to the cited retention policy's tenant/class/purpose.
- `support_edge` identity gate: support, contradiction, summary, and `outcome_of` edges cannot become state transitions; recovered evidential kinds match known truth at a higher computed rate than collapsing every kind to support (ADR 0002/0003).
- `persistence_postgres` retention/deletion/legal-hold (migration `0007`): policy rows, legal holds that block completed deletion, evidence tombstones without raw-source restore, analysis exclusion only for `logical_revocation`/`identity_tombstone` (not `cache_export_removal`), and deletion requests bound to the cited retention policy's tenant/class/purpose.
- `system_clock` identity gate: event, assertion, document, availability, and knowledge-cutoff time cannot stand in for system time; recovered system stamps match known truth at a higher computed rate than treating every stamp as event time (ADR 0002).
Expand Down
4 changes: 4 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 2 additions & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ members = [
"crates/tepp_simulation",
"crates/validation_core",
"crates/tepp_api",
"crates/inferred_status",
"crates/support_edge",
"crates/system_clock",
"crates/event_clock",
Expand Down Expand Up @@ -46,6 +47,7 @@ default-members = [
"crates/tepp_simulation",
"crates/validation_core",
"crates/tepp_api",
"crates/inferred_status",
"crates/support_edge",
"crates/system_clock",
"crates/event_clock",
Expand Down
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,7 @@ crates/corpus_split
crates/tepp_simulation
crates/validation_core
crates/tepp_api
crates/inferred_status
crates/support_edge
crates/system_clock
crates/event_clock
Expand Down
17 changes: 17 additions & 0 deletions crates/inferred_status/Cargo.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
[package]
name = "inferred_status"
description = "Inferred relations cannot be promoted to observed evidence or transitions."
version.workspace = true
edition.workspace = true
rust-version.workspace = true
license.workspace = true
authors.workspace = true
repository.workspace = true
homepage.workspace = true
readme.workspace = true
keywords.workspace = true
categories.workspace = true
publish = false

[lints]
workspace = true
53 changes: 53 additions & 0 deletions crates/inferred_status/src/error.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
//! Fail-closed inferred-status errors.

use std::fmt;

/// A fail-closed inferred-status error.
#[derive(Clone, Copy, Debug, Eq, PartialEq)]
#[non_exhaustive]
pub enum InferredStatusError {
/// An inferred relation was treated as observed evidence.
InferredIsNotObserved,
/// An inferred relation was treated as a state transition.
InferredIsNotTransition,
/// A recovery slice was empty or length-mismatched.
InvalidStatusPayload,
}

impl fmt::Display for InferredStatusError {
fn fmt(&self, formatter: &mut fmt::Formatter<'_>) -> fmt::Result {
let message = match self {
Self::InferredIsNotObserved => "inferred relation is not observed evidence",
Self::InferredIsNotTransition => "inferred relation is not a state transition",
Self::InvalidStatusPayload => "invalid inferred-status payload",
};
formatter.write_str(message)
}
}

impl std::error::Error for InferredStatusError {}

#[cfg(test)]
mod tests {
use super::InferredStatusError;

#[test]
fn error_messages_are_stable() {
for (error, message) in [
(
InferredStatusError::InferredIsNotObserved,
"inferred relation is not observed evidence",
),
(
InferredStatusError::InferredIsNotTransition,
"inferred relation is not a state transition",
),
(
InferredStatusError::InvalidStatusPayload,
"invalid inferred-status payload",
),
] {
assert_eq!(error.to_string(), message);
}
}
}
23 changes: 23 additions & 0 deletions crates/inferred_status/src/lib.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
#![forbid(unsafe_code)]
#![deny(missing_docs)]
#![allow(clippy::cast_precision_loss)]
//! Inferred relations cannot be promoted to observed evidence or transitions.
//!
//! LLM, reasoner, and heuristic proposals stay inferred until deterministic
//! schema, evidence, and scientific validation promote them (ADR 0003).

mod error;
mod status;

/// Fail-closed inferred-status errors.
pub use error::InferredStatusError;
/// Closed vocabulary of presence evidence that is not yet a transition.
pub use status::EvidenceStatus;
/// Fraction of recovered evidence statuses that match known truth.
pub use status::identity_recovery_rate;
/// Refuse to treat an inferred relation as observed evidence.
pub use status::refuse_inferred_as_observed;
/// Refuse to treat an inferred relation as a state transition.
pub use status::refuse_inferred_as_transition;
/// Return whether a status is observed evidence.
pub use status::status_is_observed;
143 changes: 143 additions & 0 deletions crates/inferred_status/src/status.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,143 @@
//! Observed versus inferred relation evidence status.

use crate::InferredStatusError;

/// Closed vocabulary of presence evidence that is not yet a transition.
#[derive(Clone, Copy, Debug, Eq, PartialEq)]
pub enum EvidenceStatus {
/// Directly observed in source documents or authoritative systems.
Observed,
/// Derived by a model, reasoner, or heuristic and not yet promoted.
Inferred,
}

impl EvidenceStatus {
/// Return the stable wire status name.
#[must_use]
pub const fn wire_name(self) -> &'static str {
match self {
Self::Observed => "observed",
Self::Inferred => "inferred",
}
}

/// Parse a stable wire status name.
///
/// # Errors
///
/// Returns [`InferredStatusError::InvalidStatusPayload`] for unrecognized
/// names.
pub fn from_wire_name(name: &str) -> Result<Self, InferredStatusError> {
match name {
"observed" => Ok(Self::Observed),
"inferred" => Ok(Self::Inferred),
_ => Err(InferredStatusError::InvalidStatusPayload),
}
}
}

/// Return whether a status is observed evidence.
///
/// # Errors
///
/// This function is infallible for the closed vocabulary and exists to keep
/// the public comparison surface explicit.
#[allow(clippy::unnecessary_wraps)]
pub fn status_is_observed(status: EvidenceStatus) -> Result<bool, InferredStatusError> {
Ok(matches!(status, EvidenceStatus::Observed))
}

/// Refuse to treat an inferred relation as observed evidence.
///
/// # Errors
///
/// Returns [`InferredStatusError::InferredIsNotObserved`] when `status` is
/// [`EvidenceStatus::Inferred`].
pub fn refuse_inferred_as_observed(status: EvidenceStatus) -> Result<(), InferredStatusError> {
match status {
EvidenceStatus::Inferred => Err(InferredStatusError::InferredIsNotObserved),
EvidenceStatus::Observed => Ok(()),
}
}

/// Refuse to treat an inferred relation as a state transition.
///
/// # Errors
///
/// Returns [`InferredStatusError::InferredIsNotTransition`] when `status` is
/// [`EvidenceStatus::Inferred`].
pub fn refuse_inferred_as_transition(status: EvidenceStatus) -> Result<(), InferredStatusError> {
match status {
EvidenceStatus::Inferred => Err(InferredStatusError::InferredIsNotTransition),
EvidenceStatus::Observed => Ok(()),
}
}

/// Fraction of recovered evidence statuses that match known truth.
///
/// # Errors
///
/// Returns [`InferredStatusError::InvalidStatusPayload`] when either slice is
/// empty or the lengths differ.
pub fn identity_recovery_rate(
truth: &[EvidenceStatus],
decided: &[EvidenceStatus],
) -> Result<f64, InferredStatusError> {
if truth.is_empty() || truth.len() != decided.len() {
return Err(InferredStatusError::InvalidStatusPayload);
}
let mut matches = 0_u32;
for (truth_status, decided_status) in truth.iter().zip(decided) {
if truth_status == decided_status {
matches += 1;
}
}
Ok(f64::from(matches) / truth.len() as f64)
Comment on lines +89 to +95

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: False branch of match counter covered only by integration test

The unit test local_branches_cover_statuses_payloads_and_wire_names in status.rs only calls identity_recovery_rate with matching pairs, so the truth_status == decided_status false branch at status.rs is never exercised by the unit test alone. It is covered by inferred_status_contract.rs (the collapsed-status case). Since coverage is computed with cargo llvm-cov --workspace, the aggregate reaches the required 100% branch coverage, so this is not a bug — just noting the coverage dependency across test targets.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

}
Comment on lines +82 to +96

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: New crate logic is self-contained and internally consistent

The inferred_status crate (status.rs) is small and correct: identity_recovery_rate guards empty and length-mismatched slices before dividing, the refusal helpers branch exhaustively over the closed EvidenceStatus enum, and from_wire_name/wire_name round-trip. Workspace wiring (Cargo.toml members/default-members, check_workspace_contract.py EXPECTED_CRATES, README "eleven", and the docstring test asserting len(crate_roots) == len(workspace_contract.EXPECTED_CRATES)) is consistently updated, so the crate-count invariants stay aligned. No behavioral bug found.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.


#[cfg(test)]
mod tests {
use super::{
EvidenceStatus, identity_recovery_rate, refuse_inferred_as_observed,
refuse_inferred_as_transition, status_is_observed,
};
use crate::InferredStatusError;

#[test]
fn local_branches_cover_statuses_payloads_and_wire_names() {
assert_eq!(
refuse_inferred_as_observed(EvidenceStatus::Inferred),
Err(InferredStatusError::InferredIsNotObserved)
);
assert_eq!(
refuse_inferred_as_transition(EvidenceStatus::Inferred),
Err(InferredStatusError::InferredIsNotTransition)
);
refuse_inferred_as_observed(EvidenceStatus::Observed).expect("observed");
refuse_inferred_as_transition(EvidenceStatus::Observed).expect("observed");
assert!(status_is_observed(EvidenceStatus::Observed).expect("observed"));
assert!(!status_is_observed(EvidenceStatus::Inferred).expect("inferred"));
for status in [EvidenceStatus::Observed, EvidenceStatus::Inferred] {
assert_eq!(
EvidenceStatus::from_wire_name(status.wire_name()).expect("round-trip"),
status
);
}
assert_eq!(
EvidenceStatus::from_wire_name("promoted"),
Err(InferredStatusError::InvalidStatusPayload)
);
let matched =
identity_recovery_rate(&[EvidenceStatus::Inferred], &[EvidenceStatus::Inferred])
.expect("rate");
assert!((matched - 1.0).abs() < f64::EPSILON);
assert_eq!(
identity_recovery_rate(&[], &[]),
Err(InferredStatusError::InvalidStatusPayload)
);
assert_eq!(
identity_recovery_rate(&[EvidenceStatus::Inferred], &[]),
Err(InferredStatusError::InvalidStatusPayload)
);
}
}
7 changes: 7 additions & 0 deletions crates/inferred_status/tests/crate_contract.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
//! Integration contract for the `inferred_status` package identity.

#[test]
fn package_identity_is_stable() {
let observed = std::hint::black_box(env!("CARGO_PKG_NAME"));
assert_eq!(observed, "inferred_status");
}
70 changes: 70 additions & 0 deletions crates/inferred_status/tests/inferred_status_contract.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,70 @@
//! Inferred relations cannot be promoted to observed evidence or transitions.

use inferred_status::{
EvidenceStatus, InferredStatusError, identity_recovery_rate, refuse_inferred_as_observed,
refuse_inferred_as_transition, status_is_observed,
};

#[test]
fn inferred_status_cannot_become_observed_or_a_transition() {
assert_eq!(
refuse_inferred_as_observed(EvidenceStatus::Inferred),
Err(InferredStatusError::InferredIsNotObserved)
);
assert_eq!(
refuse_inferred_as_transition(EvidenceStatus::Inferred),
Err(InferredStatusError::InferredIsNotTransition)
);
refuse_inferred_as_observed(EvidenceStatus::Observed).expect("observed stays observed");
refuse_inferred_as_transition(EvidenceStatus::Observed)
.expect("observed may be considered for promotion elsewhere");
assert!(status_is_observed(EvidenceStatus::Observed).expect("observed"));
assert!(!status_is_observed(EvidenceStatus::Inferred).expect("inferred"));
}

#[test]
fn recovered_statuses_match_known_truth_better_than_an_observed_collapse() {
let truth = [
EvidenceStatus::Observed,
EvidenceStatus::Inferred,
EvidenceStatus::Inferred,
];
let recovered = truth;
let collapsed = [
EvidenceStatus::Observed,
EvidenceStatus::Observed,
EvidenceStatus::Observed,
];
let recovered_rate = identity_recovery_rate(&truth, &recovered).expect("recovered");
let collapsed_rate = identity_recovery_rate(&truth, &collapsed).expect("collapsed");
let expected = {
let mut matches = 0_u32;
for (truth_status, decided_status) in truth.iter().zip(recovered.iter()) {
if truth_status == decided_status {
matches += 1;
}
}
f64::from(matches) / f64::from(u32::try_from(truth.len()).expect("len"))
};
assert!((recovered_rate - expected).abs() < f64::EPSILON);
assert!(recovered_rate > collapsed_rate);
}

#[test]
fn empty_or_mismatched_status_payloads_fail_closed() {
assert_eq!(
identity_recovery_rate(&[], &[]),
Err(InferredStatusError::InvalidStatusPayload)
);
assert_eq!(
identity_recovery_rate(&[EvidenceStatus::Inferred], &[]),
Err(InferredStatusError::InvalidStatusPayload)
);
assert_eq!(
identity_recovery_rate(
&[EvidenceStatus::Observed, EvidenceStatus::Inferred],
&[EvidenceStatus::Observed]
),
Err(InferredStatusError::InvalidStatusPayload)
);
}
2 changes: 1 addition & 1 deletion docs/TRACEABILITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ The full APA 7th standards/literature register remains `docs/research/standards-
| Allen relation algebra/bounded closure | ADR 0002; temporal research | PR #9 `temporal_core` path-consistency on protected main | implemented-main |
| forward-only transition subgraph | PRD; ADR 0002/0003 | `relation_graph` on protected main; `support_edge` evidential-vs-transition gate on the active PR | active-PR |
| event ontology/evidence mentions | PRD; ADR 0003 | `event_core` mention/instance separation on protected main; `persistence_postgres` mention SQL implemented-main refuses mention-as-instance; event-instance SQL (#39 implemented-main) refuses inverted windows; full intelligence stack remaining | partial |
| time-varying cross-classified multiple membership | PRD; ADR 0003 | `membership_core` network on protected main; multilevel estimators remaining | partial |
| time-varying cross-classified multiple membership | PRD; ADR 0003 | `membership_core` network on protected main; `inferred_status` inferred-versus-observed identity on the active PR; multilevel estimators remaining | partial |
| leakage-safe availability/cutoff snapshots | PRD; ADR 0002/0013 | `corpus_split` on protected main | implemented-main |
| recovery metrics (RMSE, bias, coverage, graph, temporal order, Monte Carlo SE gates) | PRD; Test Strategy; ADR 0007/0014 | `validation_core` on protected main (PR #19); SE-aware Monte Carlo gates included | implemented-main |
| PostgreSQL bitemporal/lineage persistence | ADR 0013; Architecture/ERD | `persistence_postgres` on protected main as before; `revision_order` later-revision system-time gate on the active PR; remaining physical ERD constraints | partial |
Expand Down
1 change: 1 addition & 0 deletions docs/adr/0003-relational-event-multiple-membership.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
# ADR 0003 — Relational event ontology and time-varying multiple membership

**Decision status:** Accepted
**Implementation maturity:** partial — membership network and event mention/instance separation implemented-main; inferred-versus-observed identity in `inferred_status` on the active PR; typed relation graph with forward-only transitions active-PR; multilevel estimators and persistence remain accepted-target
**Implementation maturity:** partial — membership network and event mention/instance separation implemented-main; evidential-vs-transition identity in `support_edge` on the active PR; typed relation graph with forward-only transitions implemented-main; multilevel estimators and persistence remain accepted-target
**Implementation maturity:** active-PR — subevent parent-window containment in `subevent_containment` on the active PR; multilevel estimators remain accepted-target
**Implementation maturity:** partial — membership network, event mention/instance separation, and Kish ESS implemented-main; nested ICC with cross-classified/multiple-membership refusal is this increment; full multilevel/MMMC estimators and remaining persistence remain accepted-target
Expand Down
2 changes: 2 additions & 0 deletions docs/adr/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,8 @@ Read [`ADR_POLICY.md`](ADR_POLICY.md) first. **Decision status and implementatio
| ADR | Decision | Decision status | Implementation maturity | Clarification / supersession |
|---|---|---|---|---|
| [0001](0001-rust-first-modular-msa.md) | Rust-first numerical core and CPU `f64` reference | Accepted | partial | ADR 0011 owns cross-service/MSA authority; 0001 retains numerical/backend authority. |
| [0002](0002-six-clock-temporal-semantics.md) | Six-clock temporal semantics and fail-closed historical leakage prevention | Accepted | active-PR | Unmerged PR #8 is the canonical Task 3 replacement implementing typed clocks/intervals against the current protected-main lineage; conflicted PR #5 is superseded lineage. Later graph/split enforcement remains target work. |
| [0003](0003-relational-event-multiple-membership.md) | Relational event ontology and time-varying cross-classified multiple membership | Accepted | partial | Weighted time-varying membership network/roles are implemented-main (PR #12); inferred-versus-observed identity is `inferred_status` on the active PR; full multilevel estimators and persistence remain accepted-target. ADR 0016 owns event-intelligence tasks. |
| [0002](0002-six-clock-temporal-semantics.md) | Six-clock temporal semantics and fail-closed historical leakage prevention | Accepted | active-PR | Evidential-vs-transition gate in `support_edge` on the active PR; remaining graph/split enforcement stays accepted-target. |
| [0003](0003-relational-event-multiple-membership.md) | Relational event ontology and time-varying cross-classified multiple membership | Accepted | partial | Evidential-vs-transition identity in `support_edge` on the active PR; membership network/roles remain implemented-main; full multilevel estimators and persistence remain accepted-target. ADR 0016 owns event-intelligence tasks. |
| [0002](0002-six-clock-temporal-semantics.md) | Six-clock temporal semantics and fail-closed historical leakage prevention | Accepted | active-PR | System-clock identity in `system_clock` on the active PR; remaining graph/split enforcement stays accepted-target. |
Expand Down
Loading
Loading