From c60dab796c9158b5a3075f9c2c4a20163cd79e45 Mon Sep 17 00:00:00 2001 From: Claude Date: Mon, 24 Aug 2026 19:16:45 +0000 Subject: [PATCH] chore(release): cut v0.9.0 Bump the project version from the never-tagged 0.8.0 to 0.9.0 (minor, since Unreleased contains genuinely new features, not just fixes) in pyproject.toml, crates/mlsirm-core, crates/fast-mlsirm-py, their lockfiles, and uv.lock, and fold the accumulated Unreleased notes into a new [0.9.0] - 2026-08-24 release section following the exact pattern established by 676ed7e9 (the actual merged 0.8.0 cut): add a release-0.9.0-cut.md fragment, re-render it in isolation as the new small Unreleased managed block, insert the version heading, and move the rest of the prior managed block to become flat historical content under it. Also removes the stale, never-rendered docs/changelog.d/release-0.8.0-cut.md fragment left over from the 0.8.0 release attempt that was never actually tagged or published (its two workflow_dispatch attempts failed on a changelog-fragment-drift check, since fixed). Its content is not folded into 0.9.0's notes since it is already permanently recorded at the existing [0.8.0] - 2026-08-17 section, which is left untouched as history. SECURITY.md and SUPPORT.md now advertise the 0.9.x support line, matching the same precedent commit's treatment of the supported pre-1.0 minor line. Verified: full pytest suite (5862 passed, 1 pre-existing skip), cargo test --workspace, cargo test --manifest-path crates/fast-mlsirm-py/Cargo.toml, the rust-backend-is-default assertion, and scripts/release_acceptance.py --require-rust all pass against the bumped version. Co-authored-by: Claude --- CHANGELOG.md | 55 +++++++++++-------- Cargo.lock | 2 +- SECURITY.md | 4 +- SUPPORT.md | 2 +- crates/fast-mlsirm-py/Cargo.lock | 4 +- crates/fast-mlsirm-py/Cargo.toml | 2 +- crates/mlsirm-core/Cargo.toml | 2 +- .../1015-bounded-subprocess-integrity.md | 5 -- .../1019-judge-runtime-assertion-safety.md | 5 -- ...-bank-transition-replay-callback-safety.md | 7 --- .../1034-classification-cutscore-preflight.md | 5 -- ...terprise-request-record-callback-safety.md | 5 -- ...-enterprise-observation-callback-safety.md | 5 -- ...nterprise-explicit-value-integer-safety.md | 5 -- ...-scoring-authorization-record-admission.md | 5 -- ...1049-ata-content-string-callback-safety.md | 5 -- ...1-assessment-aggregate-record-admission.md | 5 -- .../1053-bifactor-control-boundary.md | 6 -- ...-rubric-generation-text-callback-safety.md | 6 -- ...059-scoring-shared-enum-callback-safety.md | 7 --- .../1063-model-spec-record-admission.md | 5 -- .../1071-mokken-skew-recovery-contract.md | 18 ------ ...75-bounded-json-control-callback-safety.md | 5 -- ...1077-cross-engine-conformance-inventory.md | 9 --- ...077-cross-engine-conformance-provenance.md | 10 ---- .../1078-external-validation-profile.md | 8 --- .../1083-factor-retention-callback-safety.md | 5 -- .../1087-multilevel-text-callback-safety.md | 5 -- .../1090-pytest-repository-path.md | 10 ---- .../1092-conformance-execution-provenance.md | 7 --- .../1094-conformance-runtime-provenance.md | 7 --- .../1096-conformance-manifest-replay.md | 7 --- .../1098-release-source-identity.md | 6 -- .../changelog.d/1101-buyer-source-identity.md | 6 -- .../1103-benchmark-source-identity.md | 6 -- .../1105-figma-source-provenance.md | 5 -- .../1107-workflow-registry-transport.md | 5 -- ...1109-commercial-release-source-identity.md | 5 -- .../1113-enterprise-gate-source-provenance.md | 9 --- .../1115-enterprise-gate-control-callbacks.md | 6 -- ...117-changelog-fragment-marker-integrity.md | 5 -- ...1119-scoring-fingerprint-text-admission.md | 7 --- .../1121-io-duplicate-json-members.md | 8 --- docs/changelog.d/1124-io-nonfinite-json.md | 5 -- .../1125-bounded-json-interoperability.md | 5 -- .../1128-subprocess-command-admission.md | 5 -- .../1131-population-label-int64-roundtrip.md | 5 -- .../1133-bratt-control-boundary.md | 6 -- .../1135-rag-evidence-replay-integrity.md | 5 -- .../1137-rt-semantic-control-safety.md | 8 --- .../1139-polytomous-fit-control-safety.md | 8 --- docs/changelog.d/1143-essay-pointer-focus.md | 5 -- .../1148-twopl-control-callback-safety.md | 7 --- .../1150-polytomous-group-id-narrowing.md | 6 -- .../1152-cross-engine-conformance-report.md | 8 --- .../1153-cat-lossless-administration.md | 5 -- .../1154-polytomous-complex-response.md | 6 -- .../1155-crm-complex-response-admission.md | 8 --- .../1159-irtree-complex-admission.md | 7 --- .../1161-inference-complex-curvature.md | 6 -- .../1163-oakes-complex-admission.md | 6 -- .../changelog.d/1166-oakes-factor-id-int64.md | 5 -- .../changelog.d/1167-wle-complex-admission.md | 5 -- docs/changelog.d/1169-lltm-admission.md | 6 -- docs/changelog.d/1173-nominal-admission.md | 7 --- docs/changelog.d/1175-gpcm-admission.md | 7 --- .../1177-mixture-response-admission.md | 8 --- .../changelog.d/1179-ksirt-input-admission.md | 5 -- .../1185-testlet-input-admission.md | 7 --- .../1187-mixed-response-admission.md | 5 -- .../1189-subscore-complex-admission.md | 5 -- docs/changelog.d/1190-figma-adr-boundary.md | 6 -- .../1191-detect-evidence-admission.md | 10 ---- .../1197-grm-evidence-admission.md | 7 --- .../1199-linking-evidence-admission.md | 5 -- .../1201-factor-input-admission.md | 6 -- .../1203-parallel-analysis-data-admission.md | 6 -- .../1205-hofstee-control-ordering.md | 6 -- .../1207-pypi-release-publishing.md | 8 --- .../1208-exposure-item-evidence.md | 5 -- docs/changelog.d/1210-exposure-kl-evidence.md | 8 --- .../1212-deltaplot-group-admission.md | 6 -- docs/changelog.d/1214-owen-admission.md | 5 -- .../1216-exposure-epv-admission.md | 5 -- .../1218-exposure-sympson-controls.md | 6 -- .../1220-exposure-sprt-admission.md | 5 -- .../changelog.d/1222-exposure-ci-admission.md | 5 -- docs/changelog.d/1224-flexilevel-admission.md | 6 -- .../1225-equating-evidence-admission.md | 6 -- .../changelog.d/1227-test-design-admission.md | 5 -- .../1231-exposure-ccat-admission.md | 5 -- ...1235-1238-judge-weighted-score-boundary.md | 6 -- .../changelog.d/1240-rt-evidence-admission.md | 6 -- .../1241-rt-person-fit-control-safety.md | 5 -- .../1242-ebdif-evidence-admission.md | 5 -- .../1244-personfit-response-admission.md | 5 -- .../1245-dimtest-evidence-admission.md | 7 --- .../1246-rating-range-evidence-admission.md | 5 -- .../1249-reliability-evidence-admission.md | 11 ---- .../1251-pairwise-reliability-evidence.md | 5 -- docs/changelog.d/1252-icc-ratings-evidence.md | 6 -- ...60-reliability-rater-evidence-admission.md | 5 -- .../1261-security-evidence-admission.md | 7 --- .../1274-rater-installer-recovery.md | 5 -- docs/changelog.d/1300-ci-contract-drift.md | 6 -- .../565-crossed-multiple-membership-uh.md | 8 --- .../565-multilevel-finite-context-effects.md | 6 -- .../607-rag-request-replay-callback-safety.md | 5 -- ...odel-comparison-casewise-trust-boundary.md | 5 -- .../608-structural-selection-governor.md | 5 -- .../changelog.d/609-item-bank-buyer-report.md | 7 --- .../609-item-bank-suspension-concerns.md | 7 --- .../626-reference-backend-boundary.md | 11 ---- ...27-multilevel-m2-moment-covariance-rust.md | 12 ---- .../627-multilevel-m2-rust-projection.md | 5 -- .../627-structured-m2-rust-ownership.md | 11 ---- .../809-workflow-registry-transport-retry.md | 6 -- .../844-rag-metadata-callback-safety.md | 5 -- .../860-exposure-control-callback-safety.md | 5 -- ...-scoring-policy-integer-callback-safety.md | 5 -- .../870-ata-integer-callback-safety.md | 7 --- .../879-parallel-analysis-control-safety.md | 7 --- .../901-equating-remaining-control-safety.md | 7 --- .../961-fleiss-control-boundary.md | 6 -- .../974-utility-control-boundary.md | 7 --- .../980-essay-report-title-trust-boundary.md | 6 -- .../983-rotation-control-boundary.md | 6 -- .../991-rubric-text-trust-boundary.md | 6 -- .../995-essay-row-header-accessibility.md | 6 -- .../999-report-title-callback-safety.md | 5 -- docs/changelog.d/gpu-smoke-apt-deadline.md | 7 --- .../grm-recovery-evidence-retention.md | 10 ---- docs/changelog.d/release-0.8.0-cut.md | 23 -------- docs/changelog.d/release-0.9.0-cut.md | 27 +++++++++ docs/changelog.d/rust-toolchain-1.97.1.md | 7 --- .../validation-policy-callback-safety.md | 7 --- pyproject.toml | 2 +- uv.lock | 2 +- 138 files changed, 69 insertions(+), 864 deletions(-) delete mode 100644 docs/changelog.d/1015-bounded-subprocess-integrity.md delete mode 100644 docs/changelog.d/1019-judge-runtime-assertion-safety.md delete mode 100644 docs/changelog.d/1030-item-bank-transition-replay-callback-safety.md delete mode 100644 docs/changelog.d/1034-classification-cutscore-preflight.md delete mode 100644 docs/changelog.d/1040-enterprise-request-record-callback-safety.md delete mode 100644 docs/changelog.d/1042-enterprise-observation-callback-safety.md delete mode 100644 docs/changelog.d/1044-enterprise-explicit-value-integer-safety.md delete mode 100644 docs/changelog.d/1045-scoring-authorization-record-admission.md delete mode 100644 docs/changelog.d/1049-ata-content-string-callback-safety.md delete mode 100644 docs/changelog.d/1051-assessment-aggregate-record-admission.md delete mode 100644 docs/changelog.d/1053-bifactor-control-boundary.md delete mode 100644 docs/changelog.d/1057-rubric-generation-text-callback-safety.md delete mode 100644 docs/changelog.d/1059-scoring-shared-enum-callback-safety.md delete mode 100644 docs/changelog.d/1063-model-spec-record-admission.md delete mode 100644 docs/changelog.d/1071-mokken-skew-recovery-contract.md delete mode 100644 docs/changelog.d/1075-bounded-json-control-callback-safety.md delete mode 100644 docs/changelog.d/1077-cross-engine-conformance-inventory.md delete mode 100644 docs/changelog.d/1077-cross-engine-conformance-provenance.md delete mode 100644 docs/changelog.d/1078-external-validation-profile.md delete mode 100644 docs/changelog.d/1083-factor-retention-callback-safety.md delete mode 100644 docs/changelog.d/1087-multilevel-text-callback-safety.md delete mode 100644 docs/changelog.d/1090-pytest-repository-path.md delete mode 100644 docs/changelog.d/1092-conformance-execution-provenance.md delete mode 100644 docs/changelog.d/1094-conformance-runtime-provenance.md delete mode 100644 docs/changelog.d/1096-conformance-manifest-replay.md delete mode 100644 docs/changelog.d/1098-release-source-identity.md delete mode 100644 docs/changelog.d/1101-buyer-source-identity.md delete mode 100644 docs/changelog.d/1103-benchmark-source-identity.md delete mode 100644 docs/changelog.d/1105-figma-source-provenance.md delete mode 100644 docs/changelog.d/1107-workflow-registry-transport.md delete mode 100644 docs/changelog.d/1109-commercial-release-source-identity.md delete mode 100644 docs/changelog.d/1113-enterprise-gate-source-provenance.md delete mode 100644 docs/changelog.d/1115-enterprise-gate-control-callbacks.md delete mode 100644 docs/changelog.d/1117-changelog-fragment-marker-integrity.md delete mode 100644 docs/changelog.d/1119-scoring-fingerprint-text-admission.md delete mode 100644 docs/changelog.d/1121-io-duplicate-json-members.md delete mode 100644 docs/changelog.d/1124-io-nonfinite-json.md delete mode 100644 docs/changelog.d/1125-bounded-json-interoperability.md delete mode 100644 docs/changelog.d/1128-subprocess-command-admission.md delete mode 100644 docs/changelog.d/1131-population-label-int64-roundtrip.md delete mode 100644 docs/changelog.d/1133-bratt-control-boundary.md delete mode 100644 docs/changelog.d/1135-rag-evidence-replay-integrity.md delete mode 100644 docs/changelog.d/1137-rt-semantic-control-safety.md delete mode 100644 docs/changelog.d/1139-polytomous-fit-control-safety.md delete mode 100644 docs/changelog.d/1143-essay-pointer-focus.md delete mode 100644 docs/changelog.d/1148-twopl-control-callback-safety.md delete mode 100644 docs/changelog.d/1150-polytomous-group-id-narrowing.md delete mode 100644 docs/changelog.d/1152-cross-engine-conformance-report.md delete mode 100644 docs/changelog.d/1153-cat-lossless-administration.md delete mode 100644 docs/changelog.d/1154-polytomous-complex-response.md delete mode 100644 docs/changelog.d/1155-crm-complex-response-admission.md delete mode 100644 docs/changelog.d/1159-irtree-complex-admission.md delete mode 100644 docs/changelog.d/1161-inference-complex-curvature.md delete mode 100644 docs/changelog.d/1163-oakes-complex-admission.md delete mode 100644 docs/changelog.d/1166-oakes-factor-id-int64.md delete mode 100644 docs/changelog.d/1167-wle-complex-admission.md delete mode 100644 docs/changelog.d/1169-lltm-admission.md delete mode 100644 docs/changelog.d/1173-nominal-admission.md delete mode 100644 docs/changelog.d/1175-gpcm-admission.md delete mode 100644 docs/changelog.d/1177-mixture-response-admission.md delete mode 100644 docs/changelog.d/1179-ksirt-input-admission.md delete mode 100644 docs/changelog.d/1185-testlet-input-admission.md delete mode 100644 docs/changelog.d/1187-mixed-response-admission.md delete mode 100644 docs/changelog.d/1189-subscore-complex-admission.md delete mode 100644 docs/changelog.d/1190-figma-adr-boundary.md delete mode 100644 docs/changelog.d/1191-detect-evidence-admission.md delete mode 100644 docs/changelog.d/1197-grm-evidence-admission.md delete mode 100644 docs/changelog.d/1199-linking-evidence-admission.md delete mode 100644 docs/changelog.d/1201-factor-input-admission.md delete mode 100644 docs/changelog.d/1203-parallel-analysis-data-admission.md delete mode 100644 docs/changelog.d/1205-hofstee-control-ordering.md delete mode 100644 docs/changelog.d/1207-pypi-release-publishing.md delete mode 100644 docs/changelog.d/1208-exposure-item-evidence.md delete mode 100644 docs/changelog.d/1210-exposure-kl-evidence.md delete mode 100644 docs/changelog.d/1212-deltaplot-group-admission.md delete mode 100644 docs/changelog.d/1214-owen-admission.md delete mode 100644 docs/changelog.d/1216-exposure-epv-admission.md delete mode 100644 docs/changelog.d/1218-exposure-sympson-controls.md delete mode 100644 docs/changelog.d/1220-exposure-sprt-admission.md delete mode 100644 docs/changelog.d/1222-exposure-ci-admission.md delete mode 100644 docs/changelog.d/1224-flexilevel-admission.md delete mode 100644 docs/changelog.d/1225-equating-evidence-admission.md delete mode 100644 docs/changelog.d/1227-test-design-admission.md delete mode 100644 docs/changelog.d/1231-exposure-ccat-admission.md delete mode 100644 docs/changelog.d/1235-1238-judge-weighted-score-boundary.md delete mode 100644 docs/changelog.d/1240-rt-evidence-admission.md delete mode 100644 docs/changelog.d/1241-rt-person-fit-control-safety.md delete mode 100644 docs/changelog.d/1242-ebdif-evidence-admission.md delete mode 100644 docs/changelog.d/1244-personfit-response-admission.md delete mode 100644 docs/changelog.d/1245-dimtest-evidence-admission.md delete mode 100644 docs/changelog.d/1246-rating-range-evidence-admission.md delete mode 100644 docs/changelog.d/1249-reliability-evidence-admission.md delete mode 100644 docs/changelog.d/1251-pairwise-reliability-evidence.md delete mode 100644 docs/changelog.d/1252-icc-ratings-evidence.md delete mode 100644 docs/changelog.d/1260-reliability-rater-evidence-admission.md delete mode 100644 docs/changelog.d/1261-security-evidence-admission.md delete mode 100644 docs/changelog.d/1274-rater-installer-recovery.md delete mode 100644 docs/changelog.d/1300-ci-contract-drift.md delete mode 100644 docs/changelog.d/565-crossed-multiple-membership-uh.md delete mode 100644 docs/changelog.d/565-multilevel-finite-context-effects.md delete mode 100644 docs/changelog.d/607-rag-request-replay-callback-safety.md delete mode 100644 docs/changelog.d/608-model-comparison-casewise-trust-boundary.md delete mode 100644 docs/changelog.d/608-structural-selection-governor.md delete mode 100644 docs/changelog.d/609-item-bank-buyer-report.md delete mode 100644 docs/changelog.d/609-item-bank-suspension-concerns.md delete mode 100644 docs/changelog.d/626-reference-backend-boundary.md delete mode 100644 docs/changelog.d/627-multilevel-m2-moment-covariance-rust.md delete mode 100644 docs/changelog.d/627-multilevel-m2-rust-projection.md delete mode 100644 docs/changelog.d/627-structured-m2-rust-ownership.md delete mode 100644 docs/changelog.d/809-workflow-registry-transport-retry.md delete mode 100644 docs/changelog.d/844-rag-metadata-callback-safety.md delete mode 100644 docs/changelog.d/860-exposure-control-callback-safety.md delete mode 100644 docs/changelog.d/868-scoring-policy-integer-callback-safety.md delete mode 100644 docs/changelog.d/870-ata-integer-callback-safety.md delete mode 100644 docs/changelog.d/879-parallel-analysis-control-safety.md delete mode 100644 docs/changelog.d/901-equating-remaining-control-safety.md delete mode 100644 docs/changelog.d/961-fleiss-control-boundary.md delete mode 100644 docs/changelog.d/974-utility-control-boundary.md delete mode 100644 docs/changelog.d/980-essay-report-title-trust-boundary.md delete mode 100644 docs/changelog.d/983-rotation-control-boundary.md delete mode 100644 docs/changelog.d/991-rubric-text-trust-boundary.md delete mode 100644 docs/changelog.d/995-essay-row-header-accessibility.md delete mode 100644 docs/changelog.d/999-report-title-callback-safety.md delete mode 100644 docs/changelog.d/gpu-smoke-apt-deadline.md delete mode 100644 docs/changelog.d/grm-recovery-evidence-retention.md delete mode 100644 docs/changelog.d/release-0.8.0-cut.md create mode 100644 docs/changelog.d/release-0.9.0-cut.md delete mode 100644 docs/changelog.d/rust-toolchain-1.97.1.md delete mode 100644 docs/changelog.d/validation-policy-callback-safety.md diff --git a/CHANGELOG.md b/CHANGELOG.md index 16647dc99..7c8eaa540 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,6 +3,37 @@ ## Unreleased +### Changed + +#### Release cut 0.9.0 + +- Project version is bumped to 0.9.0 in `pyproject.toml`, `crates/mlsirm-core`, + and `crates/fast-mlsirm-py`. The accumulated `Unreleased` notes now form the + `[0.9.0] - 2026-08-24` release section: new governed contracts (cross-engine + conformance inventory/provenance/manifest-replay evidence, an external + validation and transportability profile, a governed structural-model + pair-decision gate, buyer-facing item-bank lifecycle reports), a new + Rust-owned crossed/weighted multiple-membership person-effects estimator + (Fox & Glas, 2001; Browne, Goldstein, & Rasbash, 2001) with CPU-threaded and + optional GPU kernels, reproducible release-tag-bound PyPI sdist/wheel + publishing, restriction of production backend selection to Rust-owned + paths (NumPy parity moved behind an explicit `fit_reference` API), a Rust + 1.97.1 toolchain pin across verification, and a broad continuation of the + hostile-callback/conversion-protocol hardening sweep across dozens of public + entry points (CAT, ATA, DIF, equating, scaling, reliability, multilevel, + response-time, fit-statistics, inference, linking, LLM-judge orchestration, + parallel-analysis, and rotation/loader concurrency, among others). +- This cut also removes the stale, never-rendered `release-0.8.0-cut.md` + fragment left over from the abandoned 0.8.0 release attempt (that version + was never actually tagged or published); its already-recorded + `[0.8.0] - 2026-08-17` section in `CHANGELOG.md` is left untouched as + history, and this release supersedes it directly. +- Released authoritative fragments are removed from `docs/changelog.d`; the + directory again holds only genuinely unreleased notes. + +## [0.9.0] - 2026-08-24 + + ### Added #### Cross-engine conformance inventory contract @@ -110,28 +141,6 @@ - Withheld checkout credentials from every Statistical Studies job so repository-controlled `cargo test` cannot reuse the Actions token. -#### Release cut 0.8.0 - -- Project version is bumped to 0.8.0 in `pyproject.toml`, `crates/mlsirm-core`, - and `crates/fast-mlsirm-py`. The accumulated `Unreleased` notes now form the - `[0.8.0] - 2026-08-17` release section: governed contract additions - (multilevel/multiple-membership/longitudinal design, structural - model-relation and leakage-safe model-validation units, post-pilot - item-bank lifecycle, RAG scoring/perturbation-anchor/facets-calibration - adapters, enterprise issue-intelligence observation/calibration/reporting - contracts, essay facets/score/validation HTML reports, paired rating-range - and essay-facets synthetic recovery evidence), a broad Rust-ownership - hardening sweep across dozens of public entry points (CAT, ATA, DIF, - equating, scaling, reliability, multilevel, response-time, fit-statistics, - inference, linking, LLM-judge orchestration, parallel-analysis, plausible - values, Rasch-CML, model-comparison, and rotation/loader concurrency) that - reject hostile Python callback/conversion-protocol inputs before native - dispatch, and accessibility/documentation polish (exact-value tooltips, - tabular numerals, print styles, row headers, architecture baseline, - Python 3.14 CI). -- Released authoritative fragments are removed from `docs/changelog.d`; the - directory again holds only genuinely unreleased notes. - #### Pin Rust 1.97.1 across verification - Pin local Rust builds, Python/Rust package verification, ordinary Rust tests, GPU smoke, packaging, and scheduled statistical studies to exact Rust 1.97.1 instead of a floating stable channel. @@ -713,7 +722,7 @@ - Reject caller-defined string and numeric subclasses at `ValidationPolicy` construction before `strip`, numeric conversion, or comparison callbacks can execute. - Normalize only exact built-in and package-trusted NumPy real scalar identities for scoring-policy thresholds while preserving the existing closed `0..1` domains and Rust-owned pass/fail arithmetic. - Require an exact built-in integer for `min_subgroup_n` before range comparison and preserve the existing `rust_kwargs()` payload contract. - + ## [0.8.0] - 2026-08-17 diff --git a/Cargo.lock b/Cargo.lock index a253feac1..c80ced9d8 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -442,7 +442,7 @@ checksum = "0ceec5bc11778974d1bcb055b18002eba7f4b3518b6a0081b3af5f21666da9ad" [[package]] name = "mlsirm-core" -version = "0.8.0" +version = "0.9.0" dependencies = [ "bytemuck", "pollster", diff --git a/SECURITY.md b/SECURITY.md index a3bacd013..d817b0591 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -8,8 +8,8 @@ notice explicitly says otherwise. | Version | Supported | | --- | --- | -| 0.8.x | Yes | -| < 0.8 | No | +| 0.9.x | Yes | +| < 0.9 | No | ## Reporting a Vulnerability diff --git a/SUPPORT.md b/SUPPORT.md index d1e724243..d3b28eaa1 100644 --- a/SUPPORT.md +++ b/SUPPORT.md @@ -2,7 +2,7 @@ ## Current Pre-1.0 Support Scope -`fast-mlsirm` 0.8.x is the current supported pre-1.0 minor line. Support applies +`fast-mlsirm` 0.9.x is the current supported pre-1.0 minor line. Support applies to behavior that is part of a released artifact and documented public API or CLI contract. An active pull request, research plan, experimental internal helper, or roadmap item is not supported merely because it exists in the repository. diff --git a/crates/fast-mlsirm-py/Cargo.lock b/crates/fast-mlsirm-py/Cargo.lock index 32940267d..865d921ef 100644 --- a/crates/fast-mlsirm-py/Cargo.lock +++ b/crates/fast-mlsirm-py/Cargo.lock @@ -159,7 +159,7 @@ checksum = "877a4ace8713b0bcf2a4e7eec82529c029f1d0619886d18145fea96c3ffe5c0f" [[package]] name = "fast-mlsirm-py" -version = "0.8.0" +version = "0.9.0" dependencies = [ "mlsirm-core", "numpy", @@ -401,7 +401,7 @@ dependencies = [ [[package]] name = "mlsirm-core" -version = "0.8.0" +version = "0.9.0" dependencies = [ "bytemuck", "pollster", diff --git a/crates/fast-mlsirm-py/Cargo.toml b/crates/fast-mlsirm-py/Cargo.toml index 4126e9c05..3d62026d6 100644 --- a/crates/fast-mlsirm-py/Cargo.toml +++ b/crates/fast-mlsirm-py/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "fast-mlsirm-py" -version = "0.8.0" +version = "0.9.0" edition = "2021" license = "MIT" description = "PyO3 bindings for the fast-mlsirm Rust core." diff --git a/crates/mlsirm-core/Cargo.toml b/crates/mlsirm-core/Cargo.toml index ae2cbcec0..b39c2a49b 100644 --- a/crates/mlsirm-core/Cargo.toml +++ b/crates/mlsirm-core/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "mlsirm-core" -version = "0.8.0" +version = "0.9.0" edition = "2021" license = "MIT" description = "Core likelihood and gradient routines for fast-mlsirm." diff --git a/docs/changelog.d/1015-bounded-subprocess-integrity.md b/docs/changelog.d/1015-bounded-subprocess-integrity.md deleted file mode 100644 index cc34eca11..000000000 --- a/docs/changelog.d/1015-bounded-subprocess-integrity.md +++ /dev/null @@ -1,5 +0,0 @@ -# Harden bounded subprocess cleanup - -## Fixed - -- Keep governance and procurement subprocess capture bounded across stdout, stderr, execution time, decoding, and JSON parsing. POSIX cleanup now avoids re-signalling an already reaped process group, successful capture closes parent-side pipe descriptors deterministically, and timeout/overflow paths retain fail-closed evidence without weakening repository gates. diff --git a/docs/changelog.d/1019-judge-runtime-assertion-safety.md b/docs/changelog.d/1019-judge-runtime-assertion-safety.md deleted file mode 100644 index 36e0d98c3..000000000 --- a/docs/changelog.d/1019-judge-runtime-assertion-safety.md +++ /dev/null @@ -1,5 +0,0 @@ -# Keep judge runtime validation active under Python optimization - -## Fixed - -- Replace production judge and calibration invariants that relied on removable `assert` statements with explicit package-owned `ValueError` or `RuntimeError` failures, and verify that invalid response-schema admission remains fail-closed under `python -O`. diff --git a/docs/changelog.d/1030-item-bank-transition-replay-callback-safety.md b/docs/changelog.d/1030-item-bank-transition-replay-callback-safety.md deleted file mode 100644 index baff5b5c2..000000000 --- a/docs/changelog.d/1030-item-bank-transition-replay-callback-safety.md +++ /dev/null @@ -1,7 +0,0 @@ -# Item-bank transition replay callback safety - -## Fixed - -- Lifecycle transition replay now validates the exact creation-time record and evidence-reference instance state before invoking canonical serialization or fingerprint verification. -- Frozen lifecycle records mutated through Python object internals cannot shadow `_content_dict()` or evidence `to_dict()` callbacks to execute caller code while acquiring transition authority. -- This changes provenance/integrity validation only; calibration, fit, DIF, item-information, linking, exposure, drift, uncertainty, and other production psychometric arithmetic remain Rust-owned and unchanged. diff --git a/docs/changelog.d/1034-classification-cutscore-preflight.md b/docs/changelog.d/1034-classification-cutscore-preflight.md deleted file mode 100644 index d49d817d2..000000000 --- a/docs/changelog.d/1034-classification-cutscore-preflight.md +++ /dev/null @@ -1,5 +0,0 @@ -# Harden Rudner/Lee cut-score control admission - -## Fixed - -- Validate and materialize Rudner and Lee cut-score scalars before compiled Rust capability discovery, rejecting booleans, caller-defined scalar subclasses, protocol coercion providers, malformed containers, non-finite values, and conversion overflow without invoking caller conversion hooks while preserving exact built-in and concrete NumPy real scalar compatibility. Both public paths now use one canonical package-owned normalizer; cut ordering/domain checks and all classification arithmetic remain Rust-owned. diff --git a/docs/changelog.d/1040-enterprise-request-record-callback-safety.md b/docs/changelog.d/1040-enterprise-request-record-callback-safety.md deleted file mode 100644 index 67acfea04..000000000 --- a/docs/changelog.d/1040-enterprise-request-record-callback-safety.md +++ /dev/null @@ -1,5 +0,0 @@ -# Seal enterprise request record admission - -## Fixed - -- Enterprise issue scoring-request provenance now rejects caller-defined issue, stakeholder-perspective, and candidate-intervention record subclasses before reading their fingerprints or fields, preventing caller callbacks from executing during canonical record admission while preserving exact package record behavior. diff --git a/docs/changelog.d/1042-enterprise-observation-callback-safety.md b/docs/changelog.d/1042-enterprise-observation-callback-safety.md deleted file mode 100644 index 67ddd29c9..000000000 --- a/docs/changelog.d/1042-enterprise-observation-callback-safety.md +++ /dev/null @@ -1,5 +0,0 @@ -# Seal enterprise observation admission - -## Fixed - -- Enterprise issue observation admission now rejects caller-defined scoring-request, evidence-reference, and status-string subclasses before reading provenance or performing enum lookup, preventing caller callbacks during semantic validation while preserving exact package records and serialized status strings. diff --git a/docs/changelog.d/1044-enterprise-explicit-value-integer-safety.md b/docs/changelog.d/1044-enterprise-explicit-value-integer-safety.md deleted file mode 100644 index 5406714e3..000000000 --- a/docs/changelog.d/1044-enterprise-explicit-value-integer-safety.md +++ /dev/null @@ -1,5 +0,0 @@ -# Seal enterprise explicit-value integer admission - -## Fixed - -- Reject caller-defined integer subclasses for enterprise explicit-value source offsets and deterministic parser record limits before comparison or coercion callbacks can execute, while preserving exact built-in integer domains and stable validation errors. diff --git a/docs/changelog.d/1045-scoring-authorization-record-admission.md b/docs/changelog.d/1045-scoring-authorization-record-admission.md deleted file mode 100644 index 14305b179..000000000 --- a/docs/changelog.d/1045-scoring-authorization-record-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# Seal scoring engine-authorization record admission - -## Fixed - -- Reject caller-defined assessment, scoring-request, and engine-descriptor subclasses before authorization policy or provenance fields are read, preserving exact package records, stable validation errors, and existing engine-policy semantics. diff --git a/docs/changelog.d/1049-ata-content-string-callback-safety.md b/docs/changelog.d/1049-ata-content-string-callback-safety.md deleted file mode 100644 index c88fc1ecd..000000000 --- a/docs/changelog.d/1049-ata-content-string-callback-safety.md +++ /dev/null @@ -1,5 +0,0 @@ -# Seal ATA content-string callback admission - -## Security - -- Reject caller-defined string subclasses at Automated Test Assembly content-label and content-constraint-key validation boundaries before package-triggered text conversion callbacks or psychometric scoring can run, while preserving exact built-in and NumPy string scalar support. diff --git a/docs/changelog.d/1051-assessment-aggregate-record-admission.md b/docs/changelog.d/1051-assessment-aggregate-record-admission.md deleted file mode 100644 index 1fd0482c0..000000000 --- a/docs/changelog.d/1051-assessment-aggregate-record-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# Seal assessment aggregate record admission - -## Fixed - -- Assessment assembly now rejects `ConstructSpec`, `RubricSpecification`, and scoring-policy subclasses before reading package-owned provenance or construct-scope fields, preventing caller-defined attribute/fingerprint callbacks from executing during aggregate contract admission while preserving exact package records and existing cross-reference semantics. diff --git a/docs/changelog.d/1053-bifactor-control-boundary.md b/docs/changelog.d/1053-bifactor-control-boundary.md deleted file mode 100644 index 3e983a4da..000000000 --- a/docs/changelog.d/1053-bifactor-control-boundary.md +++ /dev/null @@ -1,6 +0,0 @@ -# Bifactor scoreability control trust boundary - -## Fixed - -- Hardened both public bifactor scoreability entry points so `general_factor` and `zero_tolerance` are validated and normalized before loading, uniqueness, or logit-slope materialization and before compiled-core discovery. -- Reject booleans, caller-defined numeric subclasses, and arbitrary conversion-protocol objects without executing their callbacks, while preserving concrete Python/NumPy scalar compatibility and Rust ownership of index/domain validation and all scoreability arithmetic. diff --git a/docs/changelog.d/1057-rubric-generation-text-callback-safety.md b/docs/changelog.d/1057-rubric-generation-text-callback-safety.md deleted file mode 100644 index 7efe1d1d8..000000000 --- a/docs/changelog.d/1057-rubric-generation-text-callback-safety.md +++ /dev/null @@ -1,6 +0,0 @@ -# Rubric generation text callback safety - -## Security - -- Reject caller-defined `str` subclasses at source-content, generation-contract JSON, candidate-parser JSON, static-fixture response, and live provider-output admission boundaries before caller-overridable text operations can execute. -- Preserve built-in string behavior, exact source whitespace and digests, redacted provider failures, deterministic generation provenance, and the existing Rust-owned psychometric/statistical computation boundary. diff --git a/docs/changelog.d/1059-scoring-shared-enum-callback-safety.md b/docs/changelog.d/1059-scoring-shared-enum-callback-safety.md deleted file mode 100644 index 3aa65ea9a..000000000 --- a/docs/changelog.d/1059-scoring-shared-enum-callback-safety.md +++ /dev/null @@ -1,7 +0,0 @@ -# Scoring shared enum callback safety - -## Fixed - -- Shared scoring enum admission now preserves exact enum members and accepts only exact built-in strings for serialized enum values before invoking Enum lookup. -- Caller-defined string subclasses and arbitrary non-text objects fail closed with the existing package-owned assessment error before hostile hash or equality callbacks can run. -- Added public EngineDescriptor regressions proving callback-free rejection while preserving built-in string and exact enum-member compatibility; no scoring, calibration, likelihood, estimator, ranking, utility, or psychometric arithmetic changed. diff --git a/docs/changelog.d/1063-model-spec-record-admission.md b/docs/changelog.d/1063-model-spec-record-admission.md deleted file mode 100644 index c4224098f..000000000 --- a/docs/changelog.d/1063-model-spec-record-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# Model-spec record admission - -## Fixed - -- Model resolution now admits only exact package-owned exploratory and confirmatory model records before reading their fields, so caller-defined model-spec subclasses cannot execute attribute callbacks during validation. Exact built-in/concrete NumPy factor counts and exact package model records retain their existing behavior; multidimensional exploratory estimation remains separately governed by #633. diff --git a/docs/changelog.d/1071-mokken-skew-recovery-contract.md b/docs/changelog.d/1071-mokken-skew-recovery-contract.md deleted file mode 100644 index eff203d92..000000000 --- a/docs/changelog.d/1071-mokken-skew-recovery-contract.md +++ /dev/null @@ -1,18 +0,0 @@ -# Correct skewed-population Mokken study contract - -## Fixed - -- Keep the normal-trait Monte Carlo condition as the calibrated H/recovery - contract. -- Standardize the positive-skew half-normal latent condition to the same - location and scale as the normal condition before applying the shared 1.5 - theta scale, so the study changes distribution shape without confounding - skewness with the previous approximately 28% narrower latent spread. -- Require both moment-matched latent conditions to retain the calibrated - Loevinger H band, while keeping AISP full-recovery acceptance calibrated on - the normal condition rather than treating the user-selected `c = 0.3` - cutoff as distribution-invariant. -- Preserve the exact ignored-study execution and report failures normally. -- Declare that the workflow consumes no secrets and require reviewed - `${{ secrets.NAME }}` environment injection for any future credentialed - study. diff --git a/docs/changelog.d/1075-bounded-json-control-callback-safety.md b/docs/changelog.d/1075-bounded-json-control-callback-safety.md deleted file mode 100644 index 1f4ed5f04..000000000 --- a/docs/changelog.d/1075-bounded-json-control-callback-safety.md +++ /dev/null @@ -1,5 +0,0 @@ -# Seal bounded JSON semantic-input callback boundaries - -## Fixed - -- Reject caller-defined byte/depth limit integers before comparison and caller-defined JSON text subclasses before encoding, while preserving exact built-in controls, bounded parsing semantics, and the existing descriptor/path/size/depth defenses used by repository release and governance automation. diff --git a/docs/changelog.d/1077-cross-engine-conformance-inventory.md b/docs/changelog.d/1077-cross-engine-conformance-inventory.md deleted file mode 100644 index fd892c28a..000000000 --- a/docs/changelog.d/1077-cross-engine-conformance-inventory.md +++ /dev/null @@ -1,9 +0,0 @@ -# Cross-engine conformance inventory contract - -## Added - -- Add a provider-neutral, source-free `ConformanceInventory` contract for independent numerical conformance coverage. The first slice records public estimands, parameterization and identification scope, isolated engine/version/license identity, versioned parameter-mapping and fixture/environment fingerprints, and explicit passed/failed/indeterminate/not-executed states without adding external engines as runtime, build, package, or release dependencies. This is Python validation/provenance schema work only; production psychometric and statistical arithmetic remains Rust-owned. -- Accept both full Git SHA-1 and SHA-256 commit identities so protected-main and harness provenance remains valid across repository hash-format migrations. -- Require at least one executed evidence row before a capability can claim - `covered` or `partially_covered` status. -- Revalidate exact package-owned engine, evidence, capability, and inventory records before manifest or fingerprint replay so post-construction field rebinding cannot bypass semantic-control, fingerprint, or collection admission; hostile enum controls and container subclasses fail closed before their callbacks execute. diff --git a/docs/changelog.d/1077-cross-engine-conformance-provenance.md b/docs/changelog.d/1077-cross-engine-conformance-provenance.md deleted file mode 100644 index 159b4274a..000000000 --- a/docs/changelog.d/1077-cross-engine-conformance-provenance.md +++ /dev/null @@ -1,10 +0,0 @@ -# Cross-engine conformance provenance - -## Added - -- Add optional run-level conformance provenance for the isolated harness - commit, environment, RNG seeds, parameter-mapping schema, tolerance - rationale, output fingerprints, and license classification without storing - raw responses or adding an external-engine dependency. -- Revalidate exact run-provenance state before direct manifest replay so - post-construction container rebinding fails closed before caller callbacks. diff --git a/docs/changelog.d/1078-external-validation-profile.md b/docs/changelog.d/1078-external-validation-profile.md deleted file mode 100644 index 42af84a2d..000000000 --- a/docs/changelog.d/1078-external-validation-profile.md +++ /dev/null @@ -1,8 +0,0 @@ -# External validation profile contract - -## Added - -- Add a provider-neutral, source-free `ExternalValidationProfile` contract for preregistered external-validity and transportability evidence. The first slice keeps technical, construct, transportability, fairness, and decision-utility evidence distinct; preserves explicit failed/indeterminate/not-executed states; fingerprints normalized manifests; accepts provider-neutral dataset/site identities; and rejects evidence unavailable at the declared analysis cutoff. This is validation/provenance schema work only and does not move psychometric or statistical production arithmetic out of Rust. -- Reject caller-defined profile and evidence-record subclasses before reading their fields, keeping the immutable manifest boundary free of executable attribute callbacks. -- Reject overlapping development, internal-validation, and external-validation dataset identities so a transport claim cannot silently reuse a declared development cohort. -- Revalidate exact profile and evidence state before manifest or fingerprint replay so post-construction field rebinding cannot introduce hostile enum or container callbacks or make a manifest fingerprint disagree with its emitted payload. diff --git a/docs/changelog.d/1083-factor-retention-callback-safety.md b/docs/changelog.d/1083-factor-retention-callback-safety.md deleted file mode 100644 index ca250821d..000000000 --- a/docs/changelog.d/1083-factor-retention-callback-safety.md +++ /dev/null @@ -1,5 +0,0 @@ -# Factor-retention callback safety - -## Fixed - -- Hardened governed factor-retention evidence admission so caller-defined integer and evidence-record subclasses are rejected before comparison or record-field callbacks can execute, while preserving built-in candidate counts and existing conservative retention semantics. diff --git a/docs/changelog.d/1087-multilevel-text-callback-safety.md b/docs/changelog.d/1087-multilevel-text-callback-safety.md deleted file mode 100644 index fe0a3e872..000000000 --- a/docs/changelog.d/1087-multilevel-text-callback-safety.md +++ /dev/null @@ -1,5 +0,0 @@ -# Harden multilevel text callback safety - -## Fixed - -- Require exact built-in strings for contextual schema versions, descriptive identifiers, and provenance fingerprints before comparison, normalization, regex, or encoding work, preventing caller-defined `str` subclasses from executing callbacks during multilevel and temporal contract admission. diff --git a/docs/changelog.d/1090-pytest-repository-path.md b/docs/changelog.d/1090-pytest-repository-path.md deleted file mode 100644 index 97348bb23..000000000 --- a/docs/changelog.d/1090-pytest-repository-path.md +++ /dev/null @@ -1,10 +0,0 @@ -# Make repository test imports deterministic - -## Fixed - -- Pytest now exposes both the repository root and the Python source tree from - committed configuration, so tests that materialize repository automation - scripts do not require an operator-specific `PYTHONPATH=.` workaround. -- Agent guidance now derives its advertised Python support floor from the same - `pyproject.toml` requirement guarded by repository tests, preventing stale - lower-version setup instructions from diverging from package metadata. diff --git a/docs/changelog.d/1092-conformance-execution-provenance.md b/docs/changelog.d/1092-conformance-execution-provenance.md deleted file mode 100644 index fc2e582da..000000000 --- a/docs/changelog.d/1092-conformance-execution-provenance.md +++ /dev/null @@ -1,7 +0,0 @@ -# Executed conformance provenance integrity - -## Fixed - -- Fail closed when a cross-engine conformance inventory contains executed `passed`, `failed`, or `indeterminate` evidence without exact run provenance. -- Require both raw-output and normalized-output SHA-256 identities for executed conformance runs while preserving optional output hashes for genuinely nonexecuted plans. -- Revalidate nested run provenance before applying the execution consistency gate so post-construction mutation cannot bypass package-owned admission. diff --git a/docs/changelog.d/1094-conformance-runtime-provenance.md b/docs/changelog.d/1094-conformance-runtime-provenance.md deleted file mode 100644 index 5e6fc4c79..000000000 --- a/docs/changelog.d/1094-conformance-runtime-provenance.md +++ /dev/null @@ -1,7 +0,0 @@ -# Cross-engine runtime and redistribution provenance - -## Added - -- Bind cross-engine conformance runs to an explicit container-image or environment-lock identity, operating system, architecture, model-configuration digest, convergence-controls digest, and redistribution status. -- Include the new source-free runtime identities in deterministic manifests and inventory fingerprints while preserving exact-record replay validation against post-construction mutation. -- Keep external-engine evidence isolated from production numerical ownership; no psychometric or statistical arithmetic moves out of Rust. diff --git a/docs/changelog.d/1096-conformance-manifest-replay.md b/docs/changelog.d/1096-conformance-manifest-replay.md deleted file mode 100644 index b5f64d06c..000000000 --- a/docs/changelog.d/1096-conformance-manifest-replay.md +++ /dev/null @@ -1,7 +0,0 @@ -# Strict conformance manifest replay - -## Added - -- Added `ConformanceInventory.from_manifest()` and `from_json()` to rehydrate persisted cross-engine conformance evidence through exact package-owned validation. -- Persisted manifests now fail closed on unknown or missing nested keys, caller-defined mapping/list/text subtypes, duplicate JSON object keys, non-finite JSON constants, oversized JSON payloads, fingerprint tampering, and non-canonical normalized content. -- Replay remains provenance and serialization only; production psychometric and statistical arithmetic remains Rust-first. diff --git a/docs/changelog.d/1098-release-source-identity.md b/docs/changelog.d/1098-release-source-identity.md deleted file mode 100644 index c8a2e029a..000000000 --- a/docs/changelog.d/1098-release-source-identity.md +++ /dev/null @@ -1,6 +0,0 @@ -# Fail closed on missing release source identity - -## Fixed - -- The buyer-facing release evidence index now rejects timed-out, failed, unavailable, empty, malformed, or non-canonical Git `HEAD` identity instead of allowing an otherwise complete packet to report `status: "ok"` with unreconstructable source provenance. -- Valid repositories continue to record the exact full lowercase hexadecimal source commit without changing psychometric/statistical numerical ownership. diff --git a/docs/changelog.d/1101-buyer-source-identity.md b/docs/changelog.d/1101-buyer-source-identity.md deleted file mode 100644 index 318ed37b0..000000000 --- a/docs/changelog.d/1101-buyer-source-identity.md +++ /dev/null @@ -1,6 +0,0 @@ -# Require reconstructable buyer-packet source identity - -## Fixed - -- Buyer evidence packet generation now fails closed when Git source discovery times out, fails, is unavailable, or returns an abbreviated/malformed identity instead of recording `unknown` provenance. -- Canonical full lowercase SHA-1 and SHA-256 Git object identities remain accepted, preserving interoperability without changing psychometric/statistical numerical ownership. diff --git a/docs/changelog.d/1103-benchmark-source-identity.md b/docs/changelog.d/1103-benchmark-source-identity.md deleted file mode 100644 index b99135003..000000000 --- a/docs/changelog.d/1103-benchmark-source-identity.md +++ /dev/null @@ -1,6 +0,0 @@ -# Require reconstructable benchmark source identity - -## Fixed - -- Benchmark evidence generation now fails closed when Git source discovery times out, fails, is unavailable, or returns an abbreviated/malformed identity instead of recording `unknown` provenance. -- Canonical full lowercase SHA-1 and SHA-256 Git object identities remain accepted, preserving repository interoperability without changing psychometric/statistical numerical ownership. diff --git a/docs/changelog.d/1105-figma-source-provenance.md b/docs/changelog.d/1105-figma-source-provenance.md deleted file mode 100644 index 48b905e97..000000000 --- a/docs/changelog.d/1105-figma-source-provenance.md +++ /dev/null @@ -1,5 +0,0 @@ -# Figma evidence source provenance - -## Fixed - -- Figma design-evidence manifests now fail closed when the repository source commit cannot be resolved to a canonical full lowercase SHA-1 or SHA-256 object identity, instead of emitting buyer-facing evidence with `source_commit: "unknown"` or an abbreviated/malformed revision. diff --git a/docs/changelog.d/1107-workflow-registry-transport.md b/docs/changelog.d/1107-workflow-registry-transport.md deleted file mode 100644 index f19ee6e7a..000000000 --- a/docs/changelog.d/1107-workflow-registry-transport.md +++ /dev/null @@ -1,5 +0,0 @@ -# Workflow registry transport failures - -## Fixed - -- The read-only workflow-registry audit now converts missing or inaccessible local GitHub CLI execution into a stable fail-closed `GitHubApiError`, so automation can emit bounded failure evidence instead of crashing with raw operating-system details. diff --git a/docs/changelog.d/1109-commercial-release-source-identity.md b/docs/changelog.d/1109-commercial-release-source-identity.md deleted file mode 100644 index 7061dbd99..000000000 --- a/docs/changelog.d/1109-commercial-release-source-identity.md +++ /dev/null @@ -1,5 +0,0 @@ -# Commercial release source identity - -## Fixed - -- Fail commercial release evidence generation closed when the source Git revision is unavailable or malformed, and require a canonical lowercase full SHA-1 or SHA-256 identity before provenance can be emitted. diff --git a/docs/changelog.d/1113-enterprise-gate-source-provenance.md b/docs/changelog.d/1113-enterprise-gate-source-provenance.md deleted file mode 100644 index 253035088..000000000 --- a/docs/changelog.d/1113-enterprise-gate-source-provenance.md +++ /dev/null @@ -1,9 +0,0 @@ -# Enterprise gate source-provenance hardening - -## Fixed - -- Require enterprise due-diligence manifests to bind `source_commit` to a canonical lowercase full SHA-1 or SHA-256 Git object identity instead of accepting abbreviated or arbitrary printable identifiers. -- Reject caller-defined string subclasses before text callbacks can execute at the source-provenance admission boundary, so a successful gate remains reconstructable from exact source identity. -- Restrict manifest output to a relative path inside the invocation directory and reject symlinked or tree-escaping destinations before writing. -- Write through a validated descriptor tree into a same-directory temporary file and atomically rename it into place on supported POSIX systems, so a failed write cannot truncate the previously accepted manifest. -- Preserve an existing manifest's access permissions across atomic replacement and use ordinary process file-creation permissions for a new manifest instead of forcing buyer-facing evidence to owner-only mode. diff --git a/docs/changelog.d/1115-enterprise-gate-control-callbacks.md b/docs/changelog.d/1115-enterprise-gate-control-callbacks.md deleted file mode 100644 index 7cc1faa07..000000000 --- a/docs/changelog.d/1115-enterprise-gate-control-callbacks.md +++ /dev/null @@ -1,6 +0,0 @@ -# Enterprise gate semantic-control callback safety - -## Fixed - -- Reject caller-defined string subclasses for enterprise gate names and currency codes before normalization can invoke caller text callbacks. -- Reject caller-defined integer subclasses for procurement scenario amounts before comparison while preserving the positive-integer validation contract for exact built-in values. diff --git a/docs/changelog.d/1117-changelog-fragment-marker-integrity.md b/docs/changelog.d/1117-changelog-fragment-marker-integrity.md deleted file mode 100644 index 294836e3b..000000000 --- a/docs/changelog.d/1117-changelog-fragment-marker-integrity.md +++ /dev/null @@ -1,5 +0,0 @@ -# Changelog fragment marker integrity - -## Fixed - -- Reject authoritative changelog fragments containing reserved managed-block marker literals before rendering or update, preventing nested markers from producing a changelog that fails its own next integrity check. diff --git a/docs/changelog.d/1119-scoring-fingerprint-text-admission.md b/docs/changelog.d/1119-scoring-fingerprint-text-admission.md deleted file mode 100644 index 04f93266a..000000000 --- a/docs/changelog.d/1119-scoring-fingerprint-text-admission.md +++ /dev/null @@ -1,7 +0,0 @@ -# Scoring fingerprint text admission - -## Fixed - -- Require caller-supplied SHA-256 scoring provenance to be an exact built-in string before validation or retention, preventing valid-looking string subclasses from crossing the package trust boundary as canonical fingerprints. -- Apply the same exact built-in text boundary to structured scoring error code, path, and message fields. -- Reject caller-defined scalar subclasses in bounded scoring metadata before canonicalization or digesting. diff --git a/docs/changelog.d/1121-io-duplicate-json-members.md b/docs/changelog.d/1121-io-duplicate-json-members.md deleted file mode 100644 index 212435416..000000000 --- a/docs/changelog.d/1121-io-duplicate-json-members.md +++ /dev/null @@ -1,8 +0,0 @@ -# Reject ambiguous duplicate JSON artifact members - -## Fixed - -- The shared bounded artifact JSON loader now rejects duplicate object member - names at every nesting level instead of accepting last-value-wins semantics, - while preserving its existing stable-file, UTF-8, byte, nesting, and parser - controls. diff --git a/docs/changelog.d/1124-io-nonfinite-json.md b/docs/changelog.d/1124-io-nonfinite-json.md deleted file mode 100644 index 339415427..000000000 --- a/docs/changelog.d/1124-io-nonfinite-json.md +++ /dev/null @@ -1,5 +0,0 @@ -# Strict artifact JSON constants - -## Fixed - -- Reject `NaN`, `Infinity`, and `-Infinity` by default in the shared bounded artifact JSON loader so persisted package artifacts use interoperable JSON semantics; explicit caller `parse_constant` policies remain supported. diff --git a/docs/changelog.d/1125-bounded-json-interoperability.md b/docs/changelog.d/1125-bounded-json-interoperability.md deleted file mode 100644 index ef69449e9..000000000 --- a/docs/changelog.d/1125-bounded-json-interoperability.md +++ /dev/null @@ -1,5 +0,0 @@ -# Require interoperable bounded JSON artifacts - -## Fixed - -- Reject duplicate object member names and non-standard non-finite numeric constants in the shared repository-automation bounded JSON reader, so file-backed and direct parsing use the same unambiguous RFC-compatible semantics while preserving existing size, depth, UTF-8, path-identity, and callback-safety controls. diff --git a/docs/changelog.d/1128-subprocess-command-admission.md b/docs/changelog.d/1128-subprocess-command-admission.md deleted file mode 100644 index 8c77cdeda..000000000 --- a/docs/changelog.d/1128-subprocess-command-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# Seal bounded subprocess command admission - -## Fixed - -- Reject caller-defined command-container and text-token subclasses before repository automation materializes or checks command arguments, preventing validation-time callback execution while preserving exact built-in list and tuple vectors. diff --git a/docs/changelog.d/1131-population-label-int64-roundtrip.md b/docs/changelog.d/1131-population-label-int64-roundtrip.md deleted file mode 100644 index 873adcd4c..000000000 --- a/docs/changelog.d/1131-population-label-int64-roundtrip.md +++ /dev/null @@ -1,5 +0,0 @@ -# Population-label narrowing safety - -## Fixed - -- Reject multigroup and multilevel population labels that cannot round-trip through signed 64-bit integer representation before compaction, preventing narrowing overflow from silently reordering the identified reference population while preserving valid sparse labels and the signed `int64` boundary. diff --git a/docs/changelog.d/1133-bratt-control-boundary.md b/docs/changelog.d/1133-bratt-control-boundary.md deleted file mode 100644 index ea6391906..000000000 --- a/docs/changelog.d/1133-bratt-control-boundary.md +++ /dev/null @@ -1,6 +0,0 @@ -# BRATT control admission - -## Fixed - -- Validate and normalize Bradley-Terry-with-ties reference, iteration, and tolerance controls before comparison-data materialization or compiled-core discovery, rejecting callback-bearing scalar subclasses and protocol providers while preserving trusted built-in and NumPy scalar inputs. -- Keep BRATT probability, MM-update, reference-rescaling, convergence, and log-likelihood arithmetic unchanged in the Rust core. diff --git a/docs/changelog.d/1135-rag-evidence-replay-integrity.md b/docs/changelog.d/1135-rag-evidence-replay-integrity.md deleted file mode 100644 index f9f1a6bf2..000000000 --- a/docs/changelog.d/1135-rag-evidence-replay-integrity.md +++ /dev/null @@ -1,5 +0,0 @@ -# RAG evidence limitation replay integrity - -## Fixed - -- Replay factory-derived RAG evidence limitation records before manifest or fingerprint projection so post-construction mutation fails closed before caller callbacks can execute. diff --git a/docs/changelog.d/1137-rt-semantic-control-safety.md b/docs/changelog.d/1137-rt-semantic-control-safety.md deleted file mode 100644 index 81a6a2246..000000000 --- a/docs/changelog.d/1137-rt-semantic-control-safety.md +++ /dev/null @@ -1,8 +0,0 @@ -# Response-time calibration semantic control safety - -## Fixed - -- Reject caller-defined numeric and truth-value protocols before response-time calibration controls are normalized or dispatched to the Rust core. -- Require the joint speed-accuracy Gauss-Hermite node count to be an exact supported integer instead of silently narrowing floating-point values. -- Keep required positive-finite runtime validation active under optimized Python execution instead of relying on `assert` guards that disappear with `-O`. -- Preserve positive-finite stopping, variance-floor, and fixed-speed-scale contracts while keeping all response-time likelihood and estimation arithmetic Rust-owned. diff --git a/docs/changelog.d/1139-polytomous-fit-control-safety.md b/docs/changelog.d/1139-polytomous-fit-control-safety.md deleted file mode 100644 index ca29ac321..000000000 --- a/docs/changelog.d/1139-polytomous-fit-control-safety.md +++ /dev/null @@ -1,8 +0,0 @@ -# Polytomous fit semantic control safety - -## Fixed - -- Reject caller-defined text, integer, real, and hashing protocols before GRM/GPCM calibration controls are normalized, response data are materialized, or the Rust core is discovered. -- Require calibration quadrature to use an exact supported integer node count rather than callback-capable membership or lossy coercion. -- Normalize both `NaN` and `-1` as missing polytomous responses before category validation, and report malformed response conversion through a stable package-owned numeric-input error. -- Preserve the category, iteration, and positive-finite stopping contracts while keeping the Bock-Aitkin EM/Newton estimator and all result-affecting psychometric arithmetic Rust-owned. diff --git a/docs/changelog.d/1143-essay-pointer-focus.md b/docs/changelog.d/1143-essay-pointer-focus.md deleted file mode 100644 index 18ab471f1..000000000 --- a/docs/changelog.d/1143-essay-pointer-focus.md +++ /dev/null @@ -1,5 +0,0 @@ -# Keep essay-report pointer focus modality-safe - -## Fixed - -- Suppress pointer-acquired outlines on focusable essay-report table regions and canonical JSON blocks only when `:focus-visible` is false. Keyboard navigation retains the explicit high-contrast focus indicator, and regressions reject blanket `:focus { outline: none; }` suppression. diff --git a/docs/changelog.d/1148-twopl-control-callback-safety.md b/docs/changelog.d/1148-twopl-control-callback-safety.md deleted file mode 100644 index 0d41acdb5..000000000 --- a/docs/changelog.d/1148-twopl-control-callback-safety.md +++ /dev/null @@ -1,7 +0,0 @@ -# Compensatory 2PL control trust hardening - -## Security - -- Validate and normalize `q`, `estimate_corr`, `max_iter`, `tol`, `xi_points`, and `xi_seed` before response-array materialization or native-core discovery, rejecting caller-defined scalar subclasses and arbitrary conversion/truth-value providers without executing their callbacks. -- Preserve documented built-in and concrete NumPy scalar compatibility, Gauss-Hermite node choices, positive finite tolerance, iteration and QMC/MC point limits, and the full unsigned-64 integration-seed domain while passing only normalized built-in primitives to Rust. -- Keep compensatory 2PL likelihood, integration, ECM correlation estimation, convergence, and EAP arithmetic unchanged in the Rust core. diff --git a/docs/changelog.d/1150-polytomous-group-id-narrowing.md b/docs/changelog.d/1150-polytomous-group-id-narrowing.md deleted file mode 100644 index 54c98ed90..000000000 --- a/docs/changelog.d/1150-polytomous-group-id-narrowing.md +++ /dev/null @@ -1,6 +0,0 @@ -# Reject overflowing polytomous DIF labels - -## Fixed - -- Polytomous DIF group and studied-item label/index vectors now verify signed-64-bit narrowing before compaction or Rust dispatch, preventing unsigned boundary values from wrapping negative and changing group/reference identity. -- Valid non-negative signed-64-bit and sparse/non-contiguous labels remain supported; GRM/GPCM DIF likelihood and statistical arithmetic remain Rust-owned and unchanged. diff --git a/docs/changelog.d/1152-cross-engine-conformance-report.md b/docs/changelog.d/1152-cross-engine-conformance-report.md deleted file mode 100644 index d878771ba..000000000 --- a/docs/changelog.d/1152-cross-engine-conformance-report.md +++ /dev/null @@ -1,8 +0,0 @@ -# Accessible cross-engine conformance evidence - -## Added - -- Add a deterministic standalone HTML and canonical JSON renderer for strict `ConformanceInventory` manifests, exposing capability coverage, capability × engine execution evidence, immutable inventory/run provenance, limitations, and explicit no-evidence states with exact values in text. -- Add a deterministic provenance-bound long-form JSON table so buyers can download one flat row per capability × engine evidence record without spreadsheet formula execution risk; capabilities with no independent engine remain explicit `not_executed` rows instead of disappearing or turning green. -- Escape manifest text, emit semantic table captions/headers and a restrictive no-script CSP, and state explicitly that numerical conformance is not construct validity, fairness, or high-stakes approval. -- Delegate all ingestion to strict manifest replay and keep the renderer reporting-only; no likelihood, discrepancy, RMSE/MAE, uncertainty, alignment, scoring, or other production psychometric/statistical arithmetic moves out of Rust. \ No newline at end of file diff --git a/docs/changelog.d/1153-cat-lossless-administration.md b/docs/changelog.d/1153-cat-lossless-administration.md deleted file mode 100644 index 778c95e5d..000000000 --- a/docs/changelog.d/1153-cat-lossless-administration.md +++ /dev/null @@ -1,5 +0,0 @@ -# CAT administration data integrity - -## Fixed - -- Reject administered item indices that cannot be represented losslessly as signed 64-bit identities before range/mask handling, and reject complex-valued binary responses before any real-valued coercion can discard their imaginary component. Ordinary signed indices and real 0/1 responses retain the existing Rust-owned CAT likelihood, ability-estimation, and information paths. diff --git a/docs/changelog.d/1154-polytomous-complex-response.md b/docs/changelog.d/1154-polytomous-complex-response.md deleted file mode 100644 index d38216012..000000000 --- a/docs/changelog.d/1154-polytomous-complex-response.md +++ /dev/null @@ -1,6 +0,0 @@ -# Complex-valued polytomous response admission - -## Fixed - -- Reject complex-valued polytomous response matrices before any `float64` narrowing can discard imaginary components and turn a different observed category into a valid-looking real category. -- Preserve real integer categories plus `NaN` and `-1` missingness semantics across calibration, scoring, DIF, item/person fit, and other callers of the shared response-admission boundary without changing Rust-owned psychometric arithmetic. diff --git a/docs/changelog.d/1155-crm-complex-response-admission.md b/docs/changelog.d/1155-crm-complex-response-admission.md deleted file mode 100644 index 3754b2404..000000000 --- a/docs/changelog.d/1155-crm-complex-response-admission.md +++ /dev/null @@ -1,8 +0,0 @@ -# CRM response data integrity - -## Fixed - -- Reject complex-valued continuous-response-model observations before NumPy can narrow them to `float64` and discard an imaginary component, and reject object-dtype response storage before caller-defined numeric conversion can run. -- Establish a callback-free response-evidence boundary before NumPy materialization: exact NumPy arrays and ordinary built-in list/tuple trees with package-trusted concrete Python/NumPy numeric scalars remain supported, while arbitrary array providers and caller-defined container/numeric subclasses fail closed before their protocols can execute. Exact numeric NumPy arrays nested as inert rows inside built-in containers remain compatible without admitting ndarray subclasses or object/text leaves. -- Preserve `NaN` as the CRM missing-cell marker while rejecting `+Infinity` and `-Infinity` before native discovery instead of silently reclassifying those invalid observed values as missing. Ordinary finite real-valued evidence retains the existing Rust-owned CRM fitting path. -- Bound CRM response evidence to 20,000,000 logical cells before sequence materialization or dense real-valued work. Exact broadcast arrays and exact NumPy row leaves nested in trusted built-in matrices are rejected from shape/size metadata before allocation; shared acyclic built-in subtrees retain logical-occurrence accounting without exponential re-traversal. diff --git a/docs/changelog.d/1159-irtree-complex-admission.md b/docs/changelog.d/1159-irtree-complex-admission.md deleted file mode 100644 index 9ca4b76b2..000000000 --- a/docs/changelog.d/1159-irtree-complex-admission.md +++ /dev/null @@ -1,7 +0,0 @@ -# IRTree scientific-evidence admission - -## Fixed - -- Reject complex-valued IRTree response matrices, tree mappings, and node-dimension vectors before any `float64` narrowing can discard imaginary components and change observed categories, mapping branches, or factor assignments. -- Reject arbitrary NumPy array providers, callback-bearing container/scalar subclasses, and object/text storage before package-triggered `__array__` or numeric-conversion callbacks can synthesize or replace IRTree evidence. -- Preserve exact NumPy real-numeric arrays plus exact built-in list/tuple evidence containing package-trusted Python/NumPy real scalars, including ordinary `NaN` missingness, without changing IRTree mapping semantics or psychometric estimator arithmetic. diff --git a/docs/changelog.d/1161-inference-complex-curvature.md b/docs/changelog.d/1161-inference-complex-curvature.md deleted file mode 100644 index 7f323abaa..000000000 --- a/docs/changelog.d/1161-inference-complex-curvature.md +++ /dev/null @@ -1,6 +0,0 @@ -# Complex-valued curvature admission - -## Fixed - -- Reject complex-valued Hessian and covariance matrices before any `float64` narrowing can discard imaginary components and alter second-order, covariance, or standard-error evidence. -- Keep eigendecomposition, inversion/pseudoinversion, and standard-error arithmetic in the Rust core while preserving existing real square-matrix contracts. diff --git a/docs/changelog.d/1163-oakes-complex-admission.md b/docs/changelog.d/1163-oakes-complex-admission.md deleted file mode 100644 index f09a5efc3..000000000 --- a/docs/changelog.d/1163-oakes-complex-admission.md +++ /dev/null @@ -1,6 +0,0 @@ -# Oakes uncertainty input admission - -## Fixed - -- Reject complex-valued response matrices and factor assignments before any real/integer narrowing can discard imaginary components in the public Oakes standard-error wrapper. -- Preserve existing binary-response missingness and integer factor semantics while keeping Oakes information, finite-difference, inversion, and standard-error arithmetic in the Rust core. diff --git a/docs/changelog.d/1166-oakes-factor-id-int64.md b/docs/changelog.d/1166-oakes-factor-id-int64.md deleted file mode 100644 index e68d16176..000000000 --- a/docs/changelog.d/1166-oakes-factor-id-int64.md +++ /dev/null @@ -1,5 +0,0 @@ -# Oakes factor-id signed-64 admission - -## Fixed - -- Reject Oakes `factor_id` values that cannot round-trip through signed 64-bit integer marshalling before dimension derivation or Rust uncertainty arithmetic, preventing unsigned overflow from silently changing item-to-dimension assignments. \ No newline at end of file diff --git a/docs/changelog.d/1167-wle-complex-admission.md b/docs/changelog.d/1167-wle-complex-admission.md deleted file mode 100644 index bb6993d73..000000000 --- a/docs/changelog.d/1167-wle-complex-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# WLE complex-evidence admission - -## Fixed - -- Reject complex-valued dichotomous and polytomous WLE responses and item parameters before real-valued marshalling or Rust scoring dispatch, preventing imaginary components from being silently discarded. \ No newline at end of file diff --git a/docs/changelog.d/1169-lltm-admission.md b/docs/changelog.d/1169-lltm-admission.md deleted file mode 100644 index b608af534..000000000 --- a/docs/changelog.d/1169-lltm-admission.md +++ /dev/null @@ -1,6 +0,0 @@ -# Seal LLTM data and control admission - -## Fixed - -- Reject complex-valued LLTM response matrices and explanatory-design weights before real-valued narrowing can discard their imaginary components. -- Validate Boolean, iteration, and tolerance controls before caller-owned data materialization or compiled-Rust capability discovery, while preserving trusted built-in and concrete NumPy scalar inputs and the Rust-owned LLTM estimator. diff --git a/docs/changelog.d/1173-nominal-admission.md b/docs/changelog.d/1173-nominal-admission.md deleted file mode 100644 index 11870ee76..000000000 --- a/docs/changelog.d/1173-nominal-admission.md +++ /dev/null @@ -1,7 +0,0 @@ -# Nominal-response admission hardening - -## Fixed - -- Validate nominal category, quadrature, iteration, tolerance, Monte Carlo point, and RNG-seed controls before caller response materialization, accepting only package-trusted built-in or concrete NumPy scalar identities and passing normalized primitives to Rust. -- Reject complex response evidence before real-valued narrowing and reject infinite response values instead of silently reclassifying them as missing, while preserving ordinary real/integer categories plus documented NaN/negative missingness. -- Keep nominal probabilities, marginal likelihood, estimation, integration, convergence, identification, and EAP arithmetic unchanged in the Rust numerical core. diff --git a/docs/changelog.d/1175-gpcm-admission.md b/docs/changelog.d/1175-gpcm-admission.md deleted file mode 100644 index ea91c5829..000000000 --- a/docs/changelog.d/1175-gpcm-admission.md +++ /dev/null @@ -1,7 +0,0 @@ -# GPCM admission hardening - -## Fixed - -- Validate GPCM category, quadrature, iteration, tolerance, integration-point, and RNG-seed controls before caller response materialization, admitting only package-trusted built-in or concrete NumPy scalar identities and passing normalized primitives to Rust. -- Reject complex response evidence before real-valued narrowing and reject infinite response values instead of silently reclassifying them as missing, while preserving ordinary categories plus documented NaN/negative missingness. -- Keep GPCM probabilities, marginal likelihood, estimation, integration, reflection/identification, convergence, and EAP arithmetic unchanged in the Rust numerical core. diff --git a/docs/changelog.d/1177-mixture-response-admission.md b/docs/changelog.d/1177-mixture-response-admission.md deleted file mode 100644 index 2aad33f85..000000000 --- a/docs/changelog.d/1177-mixture-response-admission.md +++ /dev/null @@ -1,8 +0,0 @@ -# Mixture-response admission hardening - -## Fixed - -- Reject complex mixture-IRT response evidence before real-valued narrowing so caller data cannot silently project onto a different observed 0/1 pattern before Rust validation. -- Reject object-dtype response storage before per-element numeric coercion, including Python complex objects and caller-defined conversion callbacks, with the package-owned real-valued input error. -- Reject positive and negative infinity instead of treating them as undocumented missing responses, while preserving `NaN` as the documented MAR missingness representation. -- Keep mixture likelihood, posterior, EM updates, restart selection, canonical class ordering, convergence, and EAP arithmetic unchanged in the Rust numerical core. diff --git a/docs/changelog.d/1179-ksirt-input-admission.md b/docs/changelog.d/1179-ksirt-input-admission.md deleted file mode 100644 index 1633c4b2e..000000000 --- a/docs/changelog.d/1179-ksirt-input-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# KSIRT input admission - -## Fixed - -- Validate and normalize KSIRT kernel/grid controls before caller array materialization or compiled-core discovery, reject complex response or bandwidth evidence before real-valued `float64` marshalling, reject object/string-like storage before per-element numeric conversion can execute caller callbacks, and reject arbitrary array-protocol providers before NumPy materialization while preserving exact NumPy arrays and plain built-in numeric sequences. The Nadaraya-Watson/OCC estimator and all production psychometric/statistical arithmetic remain Rust-owned. diff --git a/docs/changelog.d/1185-testlet-input-admission.md b/docs/changelog.d/1185-testlet-input-admission.md deleted file mode 100644 index b09e67afb..000000000 --- a/docs/changelog.d/1185-testlet-input-admission.md +++ /dev/null @@ -1,7 +0,0 @@ -# Testlet input trust hardening - -## Security - -- Validate testlet estimator semantic controls before materializing caller-owned response or testlet arrays, so invalid controls fail without executing array protocols or reaching native-core discovery. -- Reject complex and object/string-like response storage before real-valued narrowing, preventing imaginary response evidence from being discarded and preventing caller-controlled per-element numeric conversion during admission. -- Preserve the existing 0/1/NaN response contract, testlet identifiers, resource bounds, and Rust-owned marginal-ML EM, quadrature, convergence, and local-dependence arithmetic. diff --git a/docs/changelog.d/1187-mixed-response-admission.md b/docs/changelog.d/1187-mixed-response-admission.md deleted file mode 100644 index 3ca0c8674..000000000 --- a/docs/changelog.d/1187-mixed-response-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# Mixed-format response admission - -## Fixed - -- Reject complex-valued mixed-format response evidence before real-valued marshalling so imaginary components cannot be silently discarded before categorical validation and Rust-owned calibration. diff --git a/docs/changelog.d/1189-subscore-complex-admission.md b/docs/changelog.d/1189-subscore-complex-admission.md deleted file mode 100644 index 21c2b450b..000000000 --- a/docs/changelog.d/1189-subscore-complex-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# Subscore complex-evidence admission - -## Fixed - -- Reject complex-valued response and subscale-assignment evidence before real-valued marshalling so imaginary components cannot be silently discarded before Rust-owned Haberman subscore analysis. diff --git a/docs/changelog.d/1190-figma-adr-boundary.md b/docs/changelog.d/1190-figma-adr-boundary.md deleted file mode 100644 index 1b6348853..000000000 --- a/docs/changelog.d/1190-figma-adr-boundary.md +++ /dev/null @@ -1,6 +0,0 @@ -# Bind Figma buyer evidence to an authoritative ADR - -## Added - -- Record the buyer-review Figma File ID, packet-validation boundary, and - downstream Code Connect ownership in ADR-0016 and the governance index. diff --git a/docs/changelog.d/1191-detect-evidence-admission.md b/docs/changelog.d/1191-detect-evidence-admission.md deleted file mode 100644 index 44a41b833..000000000 --- a/docs/changelog.d/1191-detect-evidence-admission.md +++ /dev/null @@ -1,10 +0,0 @@ -# DETECT evidence admission hardening - -## Fixed - -- Reject complex or non-real-numeric DETECT response storage before real-valued marshalling so observed binary evidence cannot be silently projected onto different data. -- Reject complex or non-real-numeric DETECT cluster storage before partition normalization so item-to-dimension labels cannot be silently projected onto a different real partition. -- Reject arbitrary response/cluster array-protocol providers before NumPy materialization, while preserving exact NumPy arrays and plain built-in sequences of trusted real scalar values. -- Reject a self-referential or otherwise cyclic list/tuple response or cluster (for example `a = []; a.append(a)`) before flattening instead of looping until the process is killed; cycle detection tracks only the active ancestor path, so legitimate repeated/shared acyclic rows remain accepted. -- Bound compressed shared-DAG list/tuple expansion and exact NumPy-array evidence before further package materialization, preventing hidden expansion or arrays above 20,000,000 logical cells while retaining ordinary shared-row compatibility. -- Preserve Rust ownership of conditional-covariance and DETECT index arithmetic; the Python change is limited to validation and marshalling. diff --git a/docs/changelog.d/1197-grm-evidence-admission.md b/docs/changelog.d/1197-grm-evidence-admission.md deleted file mode 100644 index acf5d6014..000000000 --- a/docs/changelog.d/1197-grm-evidence-admission.md +++ /dev/null @@ -1,7 +0,0 @@ -# Graded-response evidence admission hardening - -## Fixed - -- Normalize GRM integration, iteration, category, seed, and tolerance controls before caller response materialization, without invoking arbitrary scalar coercion callbacks. -- Reject complex, non-real-numeric, and infinite response storage before real-valued marshalling so observed graded-category evidence cannot be silently projected or reclassified as missing. -- Preserve the documented `NaN`/negative missingness convention, confirmatory loading validation, and Rust ownership of GRM likelihood, integration, parameter estimation, EAP, identification, and convergence arithmetic. diff --git a/docs/changelog.d/1199-linking-evidence-admission.md b/docs/changelog.d/1199-linking-evidence-admission.md deleted file mode 100644 index 7950eb8fd..000000000 --- a/docs/changelog.d/1199-linking-evidence-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# Linking evidence admission - -## Fixed - -- Reject complex-valued or non-real-numeric fixed-item and common-item linking evidence before lossy real marshalling, caller element conversion, or compiled Rust-core discovery; reject non-finite source-theta evidence before fixed-item Rust dispatch while preserving Rust-owned linking arithmetic. diff --git a/docs/changelog.d/1201-factor-input-admission.md b/docs/changelog.d/1201-factor-input-admission.md deleted file mode 100644 index 8e2371f07..000000000 --- a/docs/changelog.d/1201-factor-input-admission.md +++ /dev/null @@ -1,6 +0,0 @@ -# Factor input admission hardening - -## Fixed - -- Reject complex and non-real-numeric factor-analysis, reliability, and Velicer MAP evidence before real-valued marshalling can alter caller data or execute object-element conversion. -- Normalize trusted `n_factors` and `max_m` integer controls before caller array materialization and Rust-core discovery while preserving concrete NumPy integer compatibility. diff --git a/docs/changelog.d/1203-parallel-analysis-data-admission.md b/docs/changelog.d/1203-parallel-analysis-data-admission.md deleted file mode 100644 index 3aeb623b6..000000000 --- a/docs/changelog.d/1203-parallel-analysis-data-admission.md +++ /dev/null @@ -1,6 +0,0 @@ -# Parallel-analysis data admission - -## Fixed - -- Reject complex and non-real-numeric caller matrices before Horn/Glorfeld parallel-analysis input is narrowed to `float64`, preventing imaginary evidence from being silently discarded or object-element numeric callbacks from running during package-owned admission. -- Preserve existing real numeric input compatibility, integer-control validation, bounded random-eigenvalue workspace policy, and Rust ownership of eigenvalue, random-benchmark, centile, and retention arithmetic. diff --git a/docs/changelog.d/1205-hofstee-control-ordering.md b/docs/changelog.d/1205-hofstee-control-ordering.md deleted file mode 100644 index fd2c22376..000000000 --- a/docs/changelog.d/1205-hofstee-control-ordering.md +++ /dev/null @@ -1,6 +0,0 @@ -# Validate Hofstee controls before score materialization - -## Fixed - -- Validate and order the four Hofstee percentage controls before caller-owned score arrays are materialized, so rejected semantic controls cannot trigger score-side array protocols before the package emits its stable validation error. -- Preserve the existing Rust-owned Hofstee ogive, intersection, fallback, and cut-score arithmetic. diff --git a/docs/changelog.d/1207-pypi-release-publishing.md b/docs/changelog.d/1207-pypi-release-publishing.md deleted file mode 100644 index 9ae71cc34..000000000 --- a/docs/changelog.d/1207-pypi-release-publishing.md +++ /dev/null @@ -1,8 +0,0 @@ -# Reproducible PyPI release publishing - -## Added - -- Added release-tag-bound sdist and wheel publication with a project-version provenance check, pinned Maturin and PyPA publisher revisions, and persisted checkout credentials disabled. -- The canonical release-tag workflow now explicitly dispatches package publication from the immutable tag, avoiding reliance on release events created with `GITHUB_TOKEN`, which do not recursively start ordinary event-triggered workflows. -- Isolated GitHub release-asset mutation from PyPI credentials, removed the unpinned runtime Twine installation path, and kept duplicate GitHub release assets and PyPI filenames fail-closed rather than silently replacing an immutable release artifact. -- PyPI publication now depends directly on the verified build artifacts rather than successful GitHub asset attachment, so a failed PyPI publication can be retried even when immutable release assets already exist and correctly reject replacement. diff --git a/docs/changelog.d/1208-exposure-item-evidence.md b/docs/changelog.d/1208-exposure-item-evidence.md deleted file mode 100644 index ed7abce42..000000000 --- a/docs/changelog.d/1208-exposure-item-evidence.md +++ /dev/null @@ -1,5 +0,0 @@ -# CAT exposure item-evidence admission - -## Fixed - -- Reject complex-valued and non-real-numeric Sympson-Hetter and a-stratified item-parameter storage before lossy `float64` marshalling or compiled-core discovery, while preserving ordinary real item banks and Rust-owned CAT exposure algorithms. diff --git a/docs/changelog.d/1210-exposure-kl-evidence.md b/docs/changelog.d/1210-exposure-kl-evidence.md deleted file mode 100644 index fe0d304f8..000000000 --- a/docs/changelog.d/1210-exposure-kl-evidence.md +++ /dev/null @@ -1,8 +0,0 @@ -# Seal Chang-Ying KL evidence admission - -## Fixed - -- Reject complex or non-real-numeric KL item-parameter storage before any lossy `float64` narrowing or Rust-core discovery. -- Require `kl_select()` administration masks to use Boolean storage rather than truth-value coercion. -- Normalize `theta0`, `delta`, and `r` only from package-trusted built-in or concrete NumPy real scalar identities before caller array work. -- Preserve contiguous `float64`/Boolean native marshalling after admission while leaving Chang-Ying KL integration and selection arithmetic Rust-owned. diff --git a/docs/changelog.d/1212-deltaplot-group-admission.md b/docs/changelog.d/1212-deltaplot-group-admission.md deleted file mode 100644 index f91bd4146..000000000 --- a/docs/changelog.d/1212-deltaplot-group-admission.md +++ /dev/null @@ -1,6 +0,0 @@ -# Delta-plot group evidence admission - -## Fixed - -- Reject non-real-numeric Delta-plot group storage before real-valued coercion, preventing textual reference/focal labels from being silently reinterpreted and object-dtype cells from executing caller numeric callbacks during Python-to-Rust admission. -- Preserve ordinary numeric and Boolean 0/1 group arrays while keeping Angoff Delta-plot psychometric arithmetic unchanged in the Rust core. diff --git a/docs/changelog.d/1214-owen-admission.md b/docs/changelog.d/1214-owen-admission.md deleted file mode 100644 index 1e547f3f6..000000000 --- a/docs/changelog.d/1214-owen-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# Owen CAT evidence admission - -## Fixed - -- Establish Owen posterior/CAT scalar, Boolean, item-array, and binary-response trust boundaries before compiled-core discovery or caller-controlled coercion. Caller-defined scalar/truth callbacks, complex/text/object item or response storage, and arbitrary array providers now fail closed while supported NumPy scalar/array evidence is normalized to inert built-in/contiguous representations. Owen posterior moments, b-matching, variance stopping, and all result-affecting psychometric arithmetic remain Rust-owned. diff --git a/docs/changelog.d/1216-exposure-epv-admission.md b/docs/changelog.d/1216-exposure-epv-admission.md deleted file mode 100644 index 1e9ec0686..000000000 --- a/docs/changelog.d/1216-exposure-epv-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# Seal EPV trust-boundary admission - -## Fixed - -- Reject caller-defined posterior scalar callbacks, lossy or non-numeric EPV item evidence, and non-Boolean administered masks before native dispatch while preserving ordinary NumPy inputs and Rust-owned predictive/variance/selection arithmetic. diff --git a/docs/changelog.d/1218-exposure-sympson-controls.md b/docs/changelog.d/1218-exposure-sympson-controls.md deleted file mode 100644 index beb807480..000000000 --- a/docs/changelog.d/1218-exposure-sympson-controls.md +++ /dev/null @@ -1,6 +0,0 @@ -# Seal Sympson-Hetter scalar control admission - -## Fixed - -- Validate package-trusted `r_max` and `tol` scalar identity and semantic domains before caller item arrays or native discovery, preserving Rust-owned Sympson-Hetter calibration, simulation, update, and stopping arithmetic. -- Preserve the Rust finite `tol >= 0` contract directly in the canonical `exposure.sympson_hetter` boundary and remove the duplicate zero-tolerance marshalling/dispatch shim. diff --git a/docs/changelog.d/1220-exposure-sprt-admission.md b/docs/changelog.d/1220-exposure-sprt-admission.md deleted file mode 100644 index 3e223c895..000000000 --- a/docs/changelog.d/1220-exposure-sprt-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# Seal SPRT evidence and control admission - -## Fixed - -- Validate package-trusted Wald SPRT scalar controls and reject coercive, textual, object, or complex item/response evidence before native dispatch, preserving Rust-owned boundaries, likelihood-ratio accumulation, first-crossing decisions, and trace arithmetic. diff --git a/docs/changelog.d/1222-exposure-ci-admission.md b/docs/changelog.d/1222-exposure-ci-admission.md deleted file mode 100644 index d0fdcb38a..000000000 --- a/docs/changelog.d/1222-exposure-ci-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# Seal CI-classification evidence and control admission - -## Fixed - -- Validate package-trusted confidence-interval classification controls and reject coercive, textual, object, or complex item/response evidence before native dispatch, preserving Rust-owned EAP, posterior-SE, interval, and strict first-crossing arithmetic. diff --git a/docs/changelog.d/1224-flexilevel-admission.md b/docs/changelog.d/1224-flexilevel-admission.md deleted file mode 100644 index 6ece90a10..000000000 --- a/docs/changelog.d/1224-flexilevel-admission.md +++ /dev/null @@ -1,6 +0,0 @@ -# Flexilevel evidence admission - -## Fixed - -- Validate Lord flexilevel item-count and platform-size controls before caller response materialization, and reject complex, textual, object-backed, lossy, or domain-invalid response/probability evidence before native-core discovery while preserving supported binary NumPy arrays, plain callback-safe 1-D/2-D list/tuple response array-likes, and finite odd-length probability vectors. Routing, red/blue self-scoring, forward recursion, score-lattice probabilities, mean, and variance remain Rust-owned. -- Preserve callback-safe list/tuple probability compatibility for package-trusted concrete NumPy real scalars as well as built-in real scalars. diff --git a/docs/changelog.d/1225-equating-evidence-admission.md b/docs/changelog.d/1225-equating-evidence-admission.md deleted file mode 100644 index 13a938848..000000000 --- a/docs/changelog.d/1225-equating-evidence-admission.md +++ /dev/null @@ -1,6 +0,0 @@ -# Observed-score equating evidence admission - -## Fixed - -- Reject complex, object-backed, and textual score/frequency evidence before lossy `float64` marshalling or compiled-Rust discovery across equivalent-groups, NEAT, kernel, presmoothing, and SEE entry points. -- Preserve real Boolean/integer/unsigned/float evidence while keeping equating, smoothing, uncertainty, and population-linking arithmetic Rust-owned. diff --git a/docs/changelog.d/1227-test-design-admission.md b/docs/changelog.d/1227-test-design-admission.md deleted file mode 100644 index 3d112787e..000000000 --- a/docs/changelog.d/1227-test-design-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# Fixed-form test assembly admission safety - -## Fixed - -- Harden fixed-form assembly so form length and content-constraint controls are normalized before caller item evidence, complex/object information cannot be projected through `float64`, content labels are admitted as text without caller stringification, and exclusion indices must fit signed 64-bit item identity without narrowing overflow before the Rust-owned greedy assembly runs. diff --git a/docs/changelog.d/1231-exposure-ccat-admission.md b/docs/changelog.d/1231-exposure-ccat-admission.md deleted file mode 100644 index 0e1e664de..000000000 --- a/docs/changelog.d/1231-exposure-ccat-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# Harden constrained-CAT evidence admission - -## Fixed - -- Validate CCAT ability, item, content-group, target, and administered-mask evidence before native dispatch; reject callback-bearing or lossy storage, require lossless non-negative integral `uintp` group marshalling, and leave constrained-CAT selection arithmetic Rust-owned. diff --git a/docs/changelog.d/1235-1238-judge-weighted-score-boundary.md b/docs/changelog.d/1235-1238-judge-weighted-score-boundary.md deleted file mode 100644 index e9ce652ef..000000000 --- a/docs/changelog.d/1235-1238-judge-weighted-score-boundary.md +++ /dev/null @@ -1,6 +0,0 @@ -# Bound the judge's weighted-score boundary - -## Fixed - -- `ContextualOrchestratorJudge.judge()`'s plain scoring path (no `category_count`, the simplest public interface) trusted the model's own self-reported top-level `score` for the accept/reject decision instead of deriving it from `criterion_scores` and each `JudgeCriterion.weight`, unlike the three `category_count`-based paths, which already discard the self-reported score in favor of a mechanically recomputed weight-aware average. A model could report a high aggregate score while giving a low score on a heavily-weighted criterion and still be accepted. Made the plain path derive `score` the same way as the other three (issue #1238). -- Rejected a non-finite aggregate criterion weight before any contextual-orchestrator transport call. `JudgeCriterion` validates each weight as finite and positive, but two individually valid weights (for example `1e308` each) could still overflow their sum to infinity; a weighted score could then silently collapse to an incorrect finite value (for example `0.0`) instead of failing closed. All three weighted-score paths now share one bounded, finite denominator (issue #1235). diff --git a/docs/changelog.d/1240-rt-evidence-admission.md b/docs/changelog.d/1240-rt-evidence-admission.md deleted file mode 100644 index 459c822ba..000000000 --- a/docs/changelog.d/1240-rt-evidence-admission.md +++ /dev/null @@ -1,6 +0,0 @@ -# Response-time evidence admission - -## Fixed - -- Reject complex, object/text, callback-bearing, and arbitrary array-provider response-time evidence before real-valued marshalling or Rust-core discovery across standalone RT calibration, joint speed-accuracy calibration, and RT person-fit diagnostics, while preserving ordinary built-in real-numeric sequence and NumPy-array inputs. -- Replaced the recursive built-in-sequence walk with an explicit stack so a deeply nested response-time list/tuple (past Python's recursion limit) or a self-referential one (`a = []; a.append(a)`) rejects with a validation error instead of crashing the process with an uncaught `RecursionError` or looping forever. diff --git a/docs/changelog.d/1241-rt-person-fit-control-safety.md b/docs/changelog.d/1241-rt-person-fit-control-safety.md deleted file mode 100644 index a206b4824..000000000 --- a/docs/changelog.d/1241-rt-person-fit-control-safety.md +++ /dev/null @@ -1,5 +0,0 @@ -# Response-time person-fit control safety - -## Fixed - -- Validate `alpha_level` and `z_fast` with callback-free concrete real-scalar admission and the Rust-owned `(0, 1)` / finite non-negative domains before native-core discovery in response-time person-fit diagnostics. diff --git a/docs/changelog.d/1242-ebdif-evidence-admission.md b/docs/changelog.d/1242-ebdif-evidence-admission.md deleted file mode 100644 index 3baa13888..000000000 --- a/docs/changelog.d/1242-ebdif-evidence-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# Empirical Bayes DIF evidence admission - -## Fixed - -- Reject arbitrary array-protocol providers and callback-bearing sequence elements before Empirical Bayes Mantel-Haenszel DIF evidence is narrowed or dispatched, while preserving exact NumPy real-numeric arrays and ordinary built-in real-numeric list/tuple vectors. diff --git a/docs/changelog.d/1244-personfit-response-admission.md b/docs/changelog.d/1244-personfit-response-admission.md deleted file mode 100644 index 137787582..000000000 --- a/docs/changelog.d/1244-personfit-response-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# Nonparametric person-fit response admission - -## Fixed - -- Reject arbitrary array-protocol providers and callback-bearing response cells before complete dichotomous person-fit evidence is materialized or dispatched, while preserving exact NumPy real-numeric arrays and ordinary built-in real-numeric list/tuple matrices. diff --git a/docs/changelog.d/1245-dimtest-evidence-admission.md b/docs/changelog.d/1245-dimtest-evidence-admission.md deleted file mode 100644 index e6d83bfb0..000000000 --- a/docs/changelog.d/1245-dimtest-evidence-admission.md +++ /dev/null @@ -1,7 +0,0 @@ -# DIMTEST evidence admission hardening - -## Fixed - -- Reject arbitrary response and AT1/AT2 array-protocol providers before NumPy materialization so caller callbacks cannot synthesize scientific evidence or subtest membership. -- Preserve exact NumPy real-numeric arrays and plain built-in sequences of trusted real scalars, plus existing complete dichotomous response and integer index semantics. -- Preserve Rust ownership of Stout DIMTEST conditional-variance, bias-correction, p-value, and retained-group arithmetic. diff --git a/docs/changelog.d/1246-rating-range-evidence-admission.md b/docs/changelog.d/1246-rating-range-evidence-admission.md deleted file mode 100644 index 0b35703e6..000000000 --- a/docs/changelog.d/1246-rating-range-evidence-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# Seal paired rating-range evidence admission - -## Fixed - -- Reject callback-bearing or subclassed caller rating containers before NumPy conversion or Rust-core discovery, while preserving exact NumPy numeric arrays and the existing ordinal category/domain checks. Paired rating-range descriptive arithmetic remains Rust-owned. diff --git a/docs/changelog.d/1249-reliability-evidence-admission.md b/docs/changelog.d/1249-reliability-evidence-admission.md deleted file mode 100644 index 8934eed50..000000000 --- a/docs/changelog.d/1249-reliability-evidence-admission.md +++ /dev/null @@ -1,11 +0,0 @@ -# Reliability evidence admission - -## Fixed - -- Reject callback-bearing, complex, or non-real-numeric caller evidence before Rust discovery in Guttman lambda, ten Berge mu, Cronbach alpha, and person-separation reliability entry points, while preserving ordinary NumPy arrays and trusted built-in sequence inputs. -- Reject over-nested or cyclic built-in sequence evidence at the public API's known 1-D/2-D rank boundary before NumPy materialization or native discovery, while preserving shared acyclic rows and trusted real-scalar sequence compatibility. -- Use one callback-free masked-array diagnostic across ICC, Guttman lambda, ten Berge mu, Cronbach alpha, person separation, and pairwise-rater reliability so masked evidence consistently tells callers to encode missingness with NaN before any native dispatch. -- Preserve historical built-in sequence compatibility when rows are exact real-numeric NumPy arrays, while retaining callback-free rejection of ndarray subclasses and non-real row storage before materialization. -- Preserve historical rater-sequence Boolean semantics without reopening caller protocols: pure Boolean built-in sequences keep the Boolean-specific diagnostic, while mixed Boolean+numeric built-in sequences retain NumPy's numeric promotion. -- Make reliability-adapter installation recover every primary sibling after an interrupted partial bind instead of treating a hardened ICC wrapper alone as proof that the whole public reliability surface was installed. -- Bound primary and rater reliability evidence to 20,000,000 logical cells before NumPy materialization or contiguous `float64` allocation, including exact broadcast views and exact NumPy leaves nested inside trusted built-in sequences. diff --git a/docs/changelog.d/1251-pairwise-reliability-evidence.md b/docs/changelog.d/1251-pairwise-reliability-evidence.md deleted file mode 100644 index f69ac9c92..000000000 --- a/docs/changelog.d/1251-pairwise-reliability-evidence.md +++ /dev/null @@ -1,5 +0,0 @@ -# Pairwise reliability evidence admission - -## Fixed - -- Validate the Pearson/Spearman pairwise-rater Fisher control and caller-owned ratings evidence before native discovery, rejecting callback-bearing or non-real evidence without changing Rust-owned correlation, ranking, Fisher-transform, or inference arithmetic. diff --git a/docs/changelog.d/1252-icc-ratings-evidence.md b/docs/changelog.d/1252-icc-ratings-evidence.md deleted file mode 100644 index 2e8d53eac..000000000 --- a/docs/changelog.d/1252-icc-ratings-evidence.md +++ /dev/null @@ -1,6 +0,0 @@ -# ICC ratings evidence admission - -## Fixed - -- Preserve callback-free ICC semantic controls while also rejecting callback-bearing, complex, Boolean, or non-real ratings before native discovery; trusted numeric arrays and built-in numeric sequences still marshal to the unchanged Rust ICC implementation. -- Preserve the established Boolean-rating diagnostic for trusted built-in/NumPy-Boolean sequences, including mixed Boolean-plus-numeric sequences whose Boolean identity NumPy would otherwise erase by numeric promotion, and preserve actionable `NaN` missingness guidance for NumPy `MaskedArray` subclasses without reopening caller-defined array or scalar callbacks. diff --git a/docs/changelog.d/1260-reliability-rater-evidence-admission.md b/docs/changelog.d/1260-reliability-rater-evidence-admission.md deleted file mode 100644 index 95aa2df76..000000000 --- a/docs/changelog.d/1260-reliability-rater-evidence-admission.md +++ /dev/null @@ -1,5 +0,0 @@ -# Remaining reliability rater-evidence admission - -## Fixed - -- Validate Krippendorff alpha, Finn reliability, Maxwell RE, and Robinson A semantic controls and rater evidence through callback-free package admission before Rust discovery, while preserving trusted numeric sequence compatibility and the existing Rust-owned agreement/reliability arithmetic. diff --git a/docs/changelog.d/1261-security-evidence-admission.md b/docs/changelog.d/1261-security-evidence-admission.md deleted file mode 100644 index ff48a5d79..000000000 --- a/docs/changelog.d/1261-security-evidence-admission.md +++ /dev/null @@ -1,7 +0,0 @@ -# Answer-copying evidence admission - -## Fixed - -- Reject callback-bearing NumPy array providers, ndarray/container subclasses, and caller-defined numeric subclasses before answer-copying evidence is materialized for Wollack omega, K-index/K1/K2/S1/S2, or GBT. -- Preserve exact NumPy numeric arrays and exact built-in list/tuple evidence containing package-trusted Python/NumPy real scalars, while keeping existing complex, dimensional, finite, index, binary, probability, and relation validation contracts. -- Keep all result-affecting answer-copying statistics and tail/regression arithmetic in the Rust numerical core; this change only hardens Python validation and marshalling. diff --git a/docs/changelog.d/1274-rater-installer-recovery.md b/docs/changelog.d/1274-rater-installer-recovery.md deleted file mode 100644 index 0c5e7d1a6..000000000 --- a/docs/changelog.d/1274-rater-installer-recovery.md +++ /dev/null @@ -1,5 +0,0 @@ -# Rater reliability installer recovery - -## Fixed - -- Recover interrupted Krippendorff/Finn/Maxwell/Robinson reliability-adapter installation by requiring the complete package-owned rater wrapper set before idempotent short-circuiting, while preserving callback-free evidence admission and Rust-owned reliability arithmetic. diff --git a/docs/changelog.d/1300-ci-contract-drift.md b/docs/changelog.d/1300-ci-contract-drift.md deleted file mode 100644 index 7949b2b51..000000000 --- a/docs/changelog.d/1300-ci-contract-drift.md +++ /dev/null @@ -1,6 +0,0 @@ -# Close CI contract drift on the toolchain pin and metadata scalar admission - -## Fixed - -- Pin the `grm-recovery` scheduled statistical-study job's `dtolnay/rust-toolchain` step to exact Rust `1.97.1`, closing a gap where it silently floated to the default stable channel while every sibling verification lane stayed pinned. -- Align `test_metadata_normalizes_string_subclasses_without_callbacks` (formerly `test_metadata_rejects_string_subclasses_before_callbacks`) with the metadata scalar admission boundary's actual, intentional behavior: caller-defined `str` subclasses are safely normalized through the inert `str.__str__` descriptor (matching the established `int`/`float` subclass handling in the same function) without invoking any subclass-defined method, rather than being rejected outright. diff --git a/docs/changelog.d/565-crossed-multiple-membership-uh.md b/docs/changelog.d/565-crossed-multiple-membership-uh.md deleted file mode 100644 index f54b9977a..000000000 --- a/docs/changelog.d/565-crossed-multiple-membership-uh.md +++ /dev/null @@ -1,8 +0,0 @@ -# Crossed multiple-membership person effects - -## Added - -- Added a Rust-owned MAP estimator of crossed / weighted multiple-membership person effects `u_h` (Fox & Glas, 2001; Browne, Goldstein, & Rasbash, 2001). Persons may belong to several groups at once; one-hot nesting remains the singleton special case of the same sparse design. -- Added a CPU-multithreaded Bernoulli score/information reduction and an optional wgpu GPU kernel for that hot loop, with f64 CPU fallback when no adapter is present. Sparse Newton accumulation stays on CPU. This slice does not estimate OLS or AR longitudinal states. -- Added `fast_mlsirm.multilevel.estimate_crossed_person_effects` and `CrossedPersonEffectResult` as marshal-only Python access, plus a true-parameter RMSE recovery test against simulated crossed membership weights. -- Enforced the binary-response contract before native discovery and again inside the Rust estimator: finite non-negative observed cells must be exactly `0` or `1`; negative and non-finite cells retain the established missing-data semantics. diff --git a/docs/changelog.d/565-multilevel-finite-context-effects.md b/docs/changelog.d/565-multilevel-finite-context-effects.md deleted file mode 100644 index c610d3109..000000000 --- a/docs/changelog.d/565-multilevel-finite-context-effects.md +++ /dev/null @@ -1,6 +0,0 @@ -# Fail closed on unsafe multilevel contextual effects - -## Fixed - -- Multilevel contextual-effect evaluation now fails closed when any referenced context random-effect value is NaN or infinite and when finite inputs overflow the weighted sum, preventing non-finite predictor results from escaping the Rust boundary while leaving unreferenced table capacity outside sparse validation work. -- Python context-effect marshalling snapshots each required mapping value once without caller-defined membership probes and normalizes hostile lookup callbacks to non-reflective package errors before native dispatch. diff --git a/docs/changelog.d/607-rag-request-replay-callback-safety.md b/docs/changelog.d/607-rag-request-replay-callback-safety.md deleted file mode 100644 index 5c96095af..000000000 --- a/docs/changelog.d/607-rag-request-replay-callback-safety.md +++ /dev/null @@ -1,5 +0,0 @@ -# Seal governed RAG request replay - -## Fixed - -- Reject caller-defined `ScoringRequest` subclasses at governed RAG perturbation and facets-calibration replay boundaries before any request field can execute caller code. Exact factory-sealed requests retain the existing provenance validation, while invalid subclasses now fail through stable non-reflective package errors. diff --git a/docs/changelog.d/608-model-comparison-casewise-trust-boundary.md b/docs/changelog.d/608-model-comparison-casewise-trust-boundary.md deleted file mode 100644 index 3cbae3375..000000000 --- a/docs/changelog.d/608-model-comparison-casewise-trust-boundary.md +++ /dev/null @@ -1,5 +0,0 @@ -# Harden model-comparison casewise numeric trust boundary - -## Fixed - -- Harden public non-nested model-comparison casewise value admission so arbitrary float-protocol objects and caller-defined numeric subclasses fail closed without executing conversion callbacks, while preserving exact Python and supported NumPy real scalars; Vuong statistics remain Rust-owned. diff --git a/docs/changelog.d/608-structural-selection-governor.md b/docs/changelog.d/608-structural-selection-governor.md deleted file mode 100644 index 4341fec30..000000000 --- a/docs/changelog.d/608-structural-selection-governor.md +++ /dev/null @@ -1,5 +0,0 @@ -# Govern structural-model pair decisions - -## Added - -- Add a governed structural-model selection gate that keeps factor retention separate from structure choice, requires explicit parameter-space relation evidence, refuses pairwise selection before the relation-appropriate LR/bootstrap/Vuong procedure, and gates any winner on recovery and intended-score interpretation evidence. The new Python surface performs validation and policy orchestration only; numerical comparison and psychometric arithmetic remain Rust-owned. diff --git a/docs/changelog.d/609-item-bank-buyer-report.md b/docs/changelog.d/609-item-bank-buyer-report.md deleted file mode 100644 index 79868baee..000000000 --- a/docs/changelog.d/609-item-bank-buyer-report.md +++ /dev/null @@ -1,7 +0,0 @@ -# Add buyer-facing item-bank lifecycle reports - -## Added - -- Added deterministic JSON and standalone accessible HTML reporting for complete governed item-bank lifecycle lineages, including current state, rubric/blueprint provenance, approved-use scope, evidence-class inventory, transition timeline, and explicit missing-evidence limitations. -- Cross-version comparability is reported only as supported when governed linking evidence is present; the report never infers comparability from a nominal score range or active lifecycle state. -- Reporting remains provenance-only: calibration, fit, DIF, information, linking, exposure, drift, and uncertainty arithmetic are referenced by exact evidence identity and are not recomputed in Python. diff --git a/docs/changelog.d/609-item-bank-suspension-concerns.md b/docs/changelog.d/609-item-bank-suspension-concerns.md deleted file mode 100644 index 92c08bb19..000000000 --- a/docs/changelog.d/609-item-bank-suspension-concerns.md +++ /dev/null @@ -1,7 +0,0 @@ -# Govern non-psychometric item-bank suspension concerns - -## Changed - -- Governed item-bank suspension and reactivation can now bind exact non-psychometric concern evidence for evidence/content validity and security/privacy findings, alongside existing DIF, drift, exposure, and linking evidence, without fabricating psychometric drift evidence. -- Suspended records bind the exact newly asserted concern classes into their content-addressed identity, and reactivation requires fresh evidence for those same classes so unrelated evidence cannot clear a quarantine. -- Reactivation rejects a historical approval or concern fingerprint even when it is presented under a replacement evidence identifier; every required reactivation artifact must bind new evidence content. diff --git a/docs/changelog.d/626-reference-backend-boundary.md b/docs/changelog.d/626-reference-backend-boundary.md deleted file mode 100644 index fe31fc475..000000000 --- a/docs/changelog.d/626-reference-backend-boundary.md +++ /dev/null @@ -1,11 +0,0 @@ -# Production backend boundary - -## Changed - -- Restrict production `FitConfig` and CLI backend selection to Rust (`rust` or - fail-closed `auto`). Move the NumPy parity fit behind the explicit - `fast_mlsirm.fit_reference` API and `fit --reference` mode, preserving - testable parity without allowing an implicit production owner switch. -- Record the resolved Rust backend for the plain unidimensional MMLE fast path - so CLI JSON and saved fit summaries report the execution owner rather than - the unresolved `auto` selector. diff --git a/docs/changelog.d/627-multilevel-m2-moment-covariance-rust.md b/docs/changelog.d/627-multilevel-m2-moment-covariance-rust.md deleted file mode 100644 index 8a1fd9bbe..000000000 --- a/docs/changelog.d/627-multilevel-m2-moment-covariance-rust.md +++ /dev/null @@ -1,12 +0,0 @@ -# Multilevel M2 moment and covariance ownership - -## Fixed - -- Move multigroup and multilevel M2 population-moment integration into the - Rust/PyO3 numerical boundary, including the shared cluster-intercept - reduction. -- Move the finite-cluster moment-covariance construction into Rust while - preserving compact-label validation, finite-cluster correction, and the - existing M2/RMSEA2 estimand. -- Keep the NumPy implementations available only as explicit parity references; - public M2 paths fail closed when the required native entry point is absent. diff --git a/docs/changelog.d/627-multilevel-m2-rust-projection.md b/docs/changelog.d/627-multilevel-m2-rust-projection.md deleted file mode 100644 index 22d680109..000000000 --- a/docs/changelog.d/627-multilevel-m2-rust-projection.md +++ /dev/null @@ -1,5 +0,0 @@ -# Multilevel M2 Rust projection - -## Fixed - -- Multilevel M2 now routes both fitted-model and cluster-robust independence projections through the compiled Rust core, failing closed when that projection entrypoint is unavailable. diff --git a/docs/changelog.d/627-structured-m2-rust-ownership.md b/docs/changelog.d/627-structured-m2-rust-ownership.md deleted file mode 100644 index 2da766f44..000000000 --- a/docs/changelog.d/627-structured-m2-rust-ownership.md +++ /dev/null @@ -1,11 +0,0 @@ -# Structured M2 Rust ownership - -## Fixed - -- Route public single-population `m2()` calls that include estimated population - moments, anchored items, or a fixed spatial coefficient through the Rust/PyO3 - M2 kernel. Missing structured native capability now fails closed instead of - entering the NumPy reference implementation. -- Preserve the existing M2 estimand and degrees-of-freedom contract while - moving finite-difference calibration and population nuisance columns into - the Rust numerical owner. diff --git a/docs/changelog.d/809-workflow-registry-transport-retry.md b/docs/changelog.d/809-workflow-registry-transport-retry.md deleted file mode 100644 index 2d4b437a9..000000000 --- a/docs/changelog.d/809-workflow-registry-transport-retry.md +++ /dev/null @@ -1,6 +0,0 @@ -# Workflow-registry audit transport retry hardening - -## Fixed - -- Expanded the read-only Actions-registry audit transport's bounded retry classifier to cover transient HTTP 403, 404, 429, and all 5xx responses, while preserving fail-closed exhaustion and immediate failure for non-transient authentication errors such as HTTP 401. -- Added direct transport regression coverage so incident audits do not misclassify one transient GitHub control-plane response as a completed inventory failure. diff --git a/docs/changelog.d/844-rag-metadata-callback-safety.md b/docs/changelog.d/844-rag-metadata-callback-safety.md deleted file mode 100644 index 8d801c407..000000000 --- a/docs/changelog.d/844-rag-metadata-callback-safety.md +++ /dev/null @@ -1,5 +0,0 @@ -# Harden RAG metadata callback safety - -## Fixed - -- Validate caller-provided RAG metadata keys exactly once before reading any values, then freeze only the captured allowlisted values. Hostile membership, key/value, duplicate-key, and key-reiteration callbacks now fail through non-reflective package errors without granting new metadata authority. diff --git a/docs/changelog.d/860-exposure-control-callback-safety.md b/docs/changelog.d/860-exposure-control-callback-safety.md deleted file mode 100644 index 56a6c0c70..000000000 --- a/docs/changelog.d/860-exposure-control-callback-safety.md +++ /dev/null @@ -1,5 +0,0 @@ -# Exposure-control scalar callback safety - -## Fixed - -- Validate CAT/exposure integer controls from exact built-in Python and genuine NumPy scalar types before caller-dispatchable coercion or Rust-core discovery, preserving integral built-in/NumPy floating controls, package-owned bounds/errors, and Rust-owned exposure, routing, scoring, posterior, recovery, and simulation arithmetic. diff --git a/docs/changelog.d/868-scoring-policy-integer-callback-safety.md b/docs/changelog.d/868-scoring-policy-integer-callback-safety.md deleted file mode 100644 index 1d7a3723b..000000000 --- a/docs/changelog.d/868-scoring-policy-integer-callback-safety.md +++ /dev/null @@ -1,5 +0,0 @@ -# Harden scoring-policy integer callback boundaries - -## Fixed - -- Reject caller-defined integer coercion at scoring-policy positive-integer boundaries before any `__index__` callback can run, while preserving exact built-in and genuine NumPy integer scalar compatibility and existing bounded `AssessmentSpecError` semantics. diff --git a/docs/changelog.d/870-ata-integer-callback-safety.md b/docs/changelog.d/870-ata-integer-callback-safety.md deleted file mode 100644 index bf35db3de..000000000 --- a/docs/changelog.d/870-ata-integer-callback-safety.md +++ /dev/null @@ -1,7 +0,0 @@ -# ATA integer callback safety - -## Fixed - -- Automated test assembly now admits only exact built-in integers and explicitly supported genuine NumPy integer scalar identities for public length, seed, exposure, content-count, and exclusion controls before normalization. -- Caller-defined Python and NumPy integer subclasses fail closed before conversion callbacks or item-information work, while existing finite-domain validation and genuine NumPy scalar compatibility are preserved. -- Added focused public-boundary regressions for hostile scalar and container controls without changing ATA information, selection, or scoring arithmetic. diff --git a/docs/changelog.d/879-parallel-analysis-control-safety.md b/docs/changelog.d/879-parallel-analysis-control-safety.md deleted file mode 100644 index f789fd1f4..000000000 --- a/docs/changelog.d/879-parallel-analysis-control-safety.md +++ /dev/null @@ -1,7 +0,0 @@ -# Parallel-analysis control trust hardening - -## Security - -- Validate `n_iterations`, `centile`, and `seed` before native-core discovery, accepting only exact built-in integers and supported concrete NumPy integer scalars while rejecting booleans, `np.bool_`, caller-defined subclasses, and conversion providers without executing their callbacks. Workspace and `u64` seed limits fail at the same pre-discovery boundary. -- Normalize nonnumeric `data` conversion failures to a package-owned `ValueError` before native-core discovery while preserving dimensionality and workspace validation for successfully converted arrays. -- Preserve the existing positive-iteration, centile `0..99`, Rust `u64` seed, and 128 MiB random-benchmark workspace limits without changing Rust-owned Horn/Glorfeld factor-retention arithmetic. diff --git a/docs/changelog.d/901-equating-remaining-control-safety.md b/docs/changelog.d/901-equating-remaining-control-safety.md deleted file mode 100644 index 0c569ed04..000000000 --- a/docs/changelog.d/901-equating-remaining-control-safety.md +++ /dev/null @@ -1,7 +0,0 @@ -# Harden remaining equating controls before native discovery - -## Changed - -- Validate circle-arc method/point/scalar controls, nominal-weights score ceilings and synthetic-population weight, and the composite-linking exponent before compiled-core discovery. -- Reject caller-defined scalar/container subclasses and arbitrary conversion providers without executing their conversion, comparison, representation, hashing, or iteration callbacks. -- Preserve exact built-in and genuine NumPy scalar compatibility while keeping circle-arc geometry, nominal-weights moments, composite-linking weight arithmetic, and all result-affecting equating mathematics in Rust. diff --git a/docs/changelog.d/961-fleiss-control-boundary.md b/docs/changelog.d/961-fleiss-control-boundary.md deleted file mode 100644 index 15076fb00..000000000 --- a/docs/changelog.d/961-fleiss-control-boundary.md +++ /dev/null @@ -1,6 +0,0 @@ -# Fleiss kappa control trust boundary - -## Fixed - -- Hardened the public Fleiss/Conger kappa control boundary so explicit category counts and exact-mode selection are validated without executing caller-defined integer, index, or truthiness callbacks before ratings materialization or compiled-core discovery. -- Preserved genuine Python/NumPy scalar compatibility, capped explicit and inferred category counts at the Rust contract maximum of 10,000, and kept all agreement arithmetic Rust-owned. diff --git a/docs/changelog.d/974-utility-control-boundary.md b/docs/changelog.d/974-utility-control-boundary.md deleted file mode 100644 index 656dd0d26..000000000 --- a/docs/changelog.d/974-utility-control-boundary.md +++ /dev/null @@ -1,7 +0,0 @@ -# Selection utility numeric trust boundary - -## Fixed - -- Hardened classical selection-utility and Taylor-Russell scalar controls so booleans, non-real objects, and non-finite values fail with package-owned validation before compiled Rust discovery. -- Prevented arbitrary caller-defined `__float__` callbacks from executing during public control marshalling while preserving genuine Python/NumPy real scalar compatibility and keeping all BCG, Naylor-Shine, and Taylor-Russell arithmetic Rust-owned. -- Normalized exact built-in integers outside the representable float range to the same package-owned validation error instead of leaking `OverflowError`. diff --git a/docs/changelog.d/980-essay-report-title-trust-boundary.md b/docs/changelog.d/980-essay-report-title-trust-boundary.md deleted file mode 100644 index 006246611..000000000 --- a/docs/changelog.d/980-essay-report-title-trust-boundary.md +++ /dev/null @@ -1,6 +0,0 @@ -# Essay report title trust boundary - -## Fixed - -- Hardened score, validation-evidence, and facets-calibration essay HTML renderers so caller-supplied titles admit only exact built-in strings, rejecting caller-controlled `str` subclasses before overridden text callbacks such as `strip()` or HTML-escaping operations can execute. -- Added hostile-string-subclass regressions that prove all three public renderers reject before callback execution or artifact creation; scoring, calibration estimation, and psychometric arithmetic remain unchanged. diff --git a/docs/changelog.d/983-rotation-control-boundary.md b/docs/changelog.d/983-rotation-control-boundary.md deleted file mode 100644 index 237129bcf..000000000 --- a/docs/changelog.d/983-rotation-control-boundary.md +++ /dev/null @@ -1,6 +0,0 @@ -# Factor-rotation semantic control trust boundary - -## Fixed - -- Reject caller-defined criterion/policy strings and boolean, integer, or real conversion protocols before factor-rotation Rust-core discovery across direct rotation, criterion-gradient, and empirical criterion-selection APIs. -- Preserve exact built-in and supported concrete NumPy scalar controls while keeping rotation objectives, gradients, multi-start optimization, convergence, bootstrap diagnostics, policy scoring, and criterion selection arithmetic Rust-owned. diff --git a/docs/changelog.d/991-rubric-text-trust-boundary.md b/docs/changelog.d/991-rubric-text-trust-boundary.md deleted file mode 100644 index de657289f..000000000 --- a/docs/changelog.d/991-rubric-text-trust-boundary.md +++ /dev/null @@ -1,6 +0,0 @@ -# Harden rubric text schema callback safety - -## Fixed - -- Harden rubric, item-blueprint, and shared scoring text/identifier schema admission so caller-defined `str` subclasses fail closed before any overridable text callback executes, while preserving normalization for exact built-in strings. -- Apply the same exact-built-in-string admission to item-bank evidence enums so lifecycle evidence cannot dispatch caller-defined equality or hash callbacks during enum lookup. diff --git a/docs/changelog.d/995-essay-row-header-accessibility.md b/docs/changelog.d/995-essay-row-header-accessibility.md deleted file mode 100644 index 989ba6e75..000000000 --- a/docs/changelog.d/995-essay-row-header-accessibility.md +++ /dev/null @@ -1,6 +0,0 @@ -# Restore semantic essay table row headers - -## Fixed - -- Mark the identity axis of governed essay facets-calibration and validation-evidence tables with explicit `` semantics. Task, rater, respondent, category/iteration, and validation-metric identities now remain programmatically associated with their row while numerical scoring and calibration arithmetic remain unchanged. -- Preserve complete table and canonical-JSON evidence when standalone reports are printed or exported to PDF by removing screen-only scroll clipping and the JSON height cap in print media. diff --git a/docs/changelog.d/999-report-title-callback-safety.md b/docs/changelog.d/999-report-title-callback-safety.md deleted file mode 100644 index 42e18ba40..000000000 --- a/docs/changelog.d/999-report-title-callback-safety.md +++ /dev/null @@ -1,5 +0,0 @@ -# Harden generic diagnostics report title callback boundary - -## Fixed - -- Reject caller-defined `str` subclasses at the public generic diagnostics-report title boundary before truth-value or HTML-escaping callbacks can run, while preserving `None` and an empty exact built-in string as requests for the report-type default title. diff --git a/docs/changelog.d/gpu-smoke-apt-deadline.md b/docs/changelog.d/gpu-smoke-apt-deadline.md deleted file mode 100644 index be9e698ee..000000000 --- a/docs/changelog.d/gpu-smoke-apt-deadline.md +++ /dev/null @@ -1,7 +0,0 @@ -# Bound GPU smoke package provisioning - -## Fixed - -- Bound Vulkan package index and installation network/lock waits with explicit APT request, retry, lock, and whole-command deadlines so a hosted-runner mirror stall fails with actionable provisioning evidence instead of consuming the full GPU job timeout. -- Route the GPU smoke job through an isolated deb822 source list backed by the canonical Ubuntu archive and security endpoints, preventing the hosted runner's `mirror+file` registry from repeatedly selecting a black-holed Azure mirror for package payloads after metadata fallback. -- Preserve the existing llvmpipe Vulkan adapter proof and explicit CPU/GPU parity test; this changes CI provisioning reliability only, not production numerical behavior. diff --git a/docs/changelog.d/grm-recovery-evidence-retention.md b/docs/changelog.d/grm-recovery-evidence-retention.md deleted file mode 100644 index a98751850..000000000 --- a/docs/changelog.d/grm-recovery-evidence-retention.md +++ /dev/null @@ -1,10 +0,0 @@ -# Dedicated GRM recovery evidence retention - -## Changed - -- Kept the 500-replication multidimensional Graded Response Model recovery - study out of pull-request CI and out of the generic 1,800-second ignored-shard - budget, then published its printed bias, RMSE, convergence, and theta - correlation lines as a 90-day Actions artifact. -- Withheld checkout credentials from every Statistical Studies job so - repository-controlled `cargo test` cannot reuse the Actions token. diff --git a/docs/changelog.d/release-0.8.0-cut.md b/docs/changelog.d/release-0.8.0-cut.md deleted file mode 100644 index 3227881e7..000000000 --- a/docs/changelog.d/release-0.8.0-cut.md +++ /dev/null @@ -1,23 +0,0 @@ -# Release cut 0.8.0 - -## Changed - -- Project version is bumped to 0.8.0 in `pyproject.toml`, `crates/mlsirm-core`, - and `crates/fast-mlsirm-py`. The accumulated `Unreleased` notes now form the - `[0.8.0] - 2026-08-17` release section: governed contract additions - (multilevel/multiple-membership/longitudinal design, structural - model-relation and leakage-safe model-validation units, post-pilot - item-bank lifecycle, RAG scoring/perturbation-anchor/facets-calibration - adapters, enterprise issue-intelligence observation/calibration/reporting - contracts, essay facets/score/validation HTML reports, paired rating-range - and essay-facets synthetic recovery evidence), a broad Rust-ownership - hardening sweep across dozens of public entry points (CAT, ATA, DIF, - equating, scaling, reliability, multilevel, response-time, fit-statistics, - inference, linking, LLM-judge orchestration, parallel-analysis, plausible - values, Rasch-CML, model-comparison, and rotation/loader concurrency) that - reject hostile Python callback/conversion-protocol inputs before native - dispatch, and accessibility/documentation polish (exact-value tooltips, - tabular numerals, print styles, row headers, architecture baseline, - Python 3.14 CI). -- Released authoritative fragments are removed from `docs/changelog.d`; the - directory again holds only genuinely unreleased notes. diff --git a/docs/changelog.d/release-0.9.0-cut.md b/docs/changelog.d/release-0.9.0-cut.md new file mode 100644 index 000000000..dd292160b --- /dev/null +++ b/docs/changelog.d/release-0.9.0-cut.md @@ -0,0 +1,27 @@ +# Release cut 0.9.0 + +## Changed + +- Project version is bumped to 0.9.0 in `pyproject.toml`, `crates/mlsirm-core`, + and `crates/fast-mlsirm-py`. The accumulated `Unreleased` notes now form the + `[0.9.0] - 2026-08-24` release section: new governed contracts (cross-engine + conformance inventory/provenance/manifest-replay evidence, an external + validation and transportability profile, a governed structural-model + pair-decision gate, buyer-facing item-bank lifecycle reports), a new + Rust-owned crossed/weighted multiple-membership person-effects estimator + (Fox & Glas, 2001; Browne, Goldstein, & Rasbash, 2001) with CPU-threaded and + optional GPU kernels, reproducible release-tag-bound PyPI sdist/wheel + publishing, restriction of production backend selection to Rust-owned + paths (NumPy parity moved behind an explicit `fit_reference` API), a Rust + 1.97.1 toolchain pin across verification, and a broad continuation of the + hostile-callback/conversion-protocol hardening sweep across dozens of public + entry points (CAT, ATA, DIF, equating, scaling, reliability, multilevel, + response-time, fit-statistics, inference, linking, LLM-judge orchestration, + parallel-analysis, and rotation/loader concurrency, among others). +- This cut also removes the stale, never-rendered `release-0.8.0-cut.md` + fragment left over from the abandoned 0.8.0 release attempt (that version + was never actually tagged or published); its already-recorded + `[0.8.0] - 2026-08-17` section in `CHANGELOG.md` is left untouched as + history, and this release supersedes it directly. +- Released authoritative fragments are removed from `docs/changelog.d`; the + directory again holds only genuinely unreleased notes. diff --git a/docs/changelog.d/rust-toolchain-1.97.1.md b/docs/changelog.d/rust-toolchain-1.97.1.md deleted file mode 100644 index b9aa720dd..000000000 --- a/docs/changelog.d/rust-toolchain-1.97.1.md +++ /dev/null @@ -1,7 +0,0 @@ -# Pin Rust 1.97.1 across verification - -## Changed - -- Pin local Rust builds, Python/Rust package verification, ordinary Rust tests, GPU smoke, packaging, and scheduled statistical studies to exact Rust 1.97.1 instead of a floating stable channel. -- Track the root `rust-toolchain.toml` through Dependabot so future stable compiler updates arrive as reviewable pull requests with exact-head scientific, package, GPU, security, and recovery evidence. -- Preserve the existing public crate compatibility boundary by not adding or raising `package.rust-version`; this is a repository build-baseline change, not a new downstream MSRV claim. diff --git a/docs/changelog.d/validation-policy-callback-safety.md b/docs/changelog.d/validation-policy-callback-safety.md deleted file mode 100644 index 2fb275c6e..000000000 --- a/docs/changelog.d/validation-policy-callback-safety.md +++ /dev/null @@ -1,7 +0,0 @@ -# Harden validation-policy scalar trust boundaries - -## Security - -- Reject caller-defined string and numeric subclasses at `ValidationPolicy` construction before `strip`, numeric conversion, or comparison callbacks can execute. -- Normalize only exact built-in and package-trusted NumPy real scalar identities for scoring-policy thresholds while preserving the existing closed `0..1` domains and Rust-owned pass/fail arithmetic. -- Require an exact built-in integer for `min_subgroup_n` before range comparison and preserve the existing `rust_kwargs()` payload contract. diff --git a/pyproject.toml b/pyproject.toml index 72b1f51bc..06da6674b 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "maturin" [project] name = "fast-mlsirm" -version = "0.8.0" +version = "0.9.0" description = "Fast simulation, fitting, and recovery diagnostics for MLSIRM/MLS2PLM models." readme = "README.md" requires-python = ">=3.12" diff --git a/uv.lock b/uv.lock index 855582802..1e1c30178 100644 --- a/uv.lock +++ b/uv.lock @@ -40,7 +40,7 @@ wheels = [ [[package]] name = "fast-mlsirm" -version = "0.8.0" +version = "0.9.0" source = { editable = "." } dependencies = [ { name = "numpy", version = "2.2.6", source = { registry = "https://pypi.org/simple" }, marker = "python_full_version < '3.11'" },