Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -61,6 +61,7 @@ boundaries above remain the target modular MSA architecture.
| `tepp_simulation` | known-truth temporal/event data generation |
| `validation_core` | RMSE, bias, coverage, graph, and Monte Carlo metrics |
| `tepp_api` | versioned DTO, schema, and export contracts |
| `stopword_deletion` | default stopword deletion is not a valid method for repeated report language |
| `copy_identity` | a template copy is not the source document and not a state transition |
| `intake_authorization` | untrusted intake fails closed without a grant; bounds are not authorization |
| `summarizes_edge` | a summary is not a state transition and not the source document |
Expand Down
2 changes: 2 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,8 @@ All notable changes to TEPP are documented here. The format follows Keep a Chang

### Added

- `stopword_deletion` method gate: a default or global stopword list cannot erase repeated report language; recovered deletion kinds match known truth at a higher computed rate than collapsing every token treatment to stopword deletion (ADR 0004/0012).
- `persistence_postgres` retention/deletion/legal-hold (migration `0007`): policy rows, legal holds that block completed deletion, evidence tombstones without raw-source restore, analysis exclusion only for `logical_revocation`/`identity_tombstone` (not `cache_export_removal`), and deletion requests bound to the cited retention policy's tenant/class/purpose.
- `copy_identity` identity gate: a template or pasted copy cannot reuse the source document identity or become a state transition; recovered copy kinds match known truth at a higher computed rate than collapsing every copy to the source (ADR 0003).
- `persistence_postgres` retention/deletion/legal-hold (migration `0007`): policy rows, legal holds that block completed deletion, evidence tombstones without raw-source restore, analysis exclusion only for `logical_revocation`/`identity_tombstone` (not `cache_export_removal`), and deletion requests bound to the cited retention policy's tenant/class/purpose.
- `provider_receipt` disclosure receipt: records provider field codes and
Expand Down
4 changes: 4 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 2 additions & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ members = [
"crates/tepp_simulation",
"crates/validation_core",
"crates/tepp_api",
"crates/stopword_deletion",
"crates/copy_identity",
"crates/provider_receipt",
"crates/intake_authorization",
Expand Down Expand Up @@ -54,6 +55,7 @@ default-members = [
"crates/tepp_simulation",
"crates/validation_core",
"crates/tepp_api",
"crates/stopword_deletion",
"crates/copy_identity",
"crates/provider_receipt",
"crates/intake_authorization",
Expand Down
1 change: 1 addition & 0 deletions DOCUMENTATION.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,7 @@ TEPP's approved PRD v0.4 and implementation plan are the primary product baselin
| Mention-confidence Brier doctoring | [`docs/research/mention-confidence-brier.md`](docs/research/mention-confidence-brier.md) |
| Event-intelligence status-gate doctoring | [`docs/research/event-intelligence-status-gates.md`](docs/research/event-intelligence-status-gates.md) |
| Retention/deletion/legal-hold doctoring | [`docs/research/retention-deletion-legal-hold.md`](docs/research/retention-deletion-legal-hold.md) |
| Stopword-deletion doctoring | [`docs/research/stopword-deletion.md`](docs/research/stopword-deletion.md) |
| Provider-payload minimization doctoring | [`docs/research/provider-payload-minimization.md`](docs/research/provider-payload-minimization.md) |
| Adaptive orchestration router doctoring | [`docs/research/adaptive-orchestration-router.md`](docs/research/adaptive-orchestration-router.md) |
| Hourly NIM OpenCode doctoring | [`docs/doctoring/hourly-nim-opencode-development.md`](docs/doctoring/hourly-nim-opencode-development.md) |
Expand Down
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,7 @@ crates/corpus_split
crates/tepp_simulation
crates/validation_core
crates/tepp_api
crates/stopword_deletion
crates/copy_identity
crates/provider_receipt
crates/intake_authorization
Expand Down
17 changes: 17 additions & 0 deletions crates/stopword_deletion/Cargo.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
[package]
name = "stopword_deletion"
description = "Default stopword deletion is not a valid method for repeated report language."
version.workspace = true
edition.workspace = true
rust-version.workspace = true
license.workspace = true
authors.workspace = true
repository.workspace = true
homepage.workspace = true
readme.workspace = true
keywords.workspace = true
categories.workspace = true
publish = false

[lints]
workspace = true
48 changes: 48 additions & 0 deletions crates/stopword_deletion/src/error.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,48 @@
//! Fail-closed stopword-deletion errors.

use std::fmt;

/// A fail-closed stopword-deletion error.
#[derive(Clone, Copy, Debug, Eq, PartialEq)]
#[non_exhaustive]
pub enum StopwordDeletionError {
/// A default or global stopword list was used as deletion.
DefaultStopwordDeletion,
/// A recovery slice was empty or length-mismatched.
InvalidDeletionPayload,
}

impl fmt::Display for StopwordDeletionError {
fn fmt(&self, formatter: &mut fmt::Formatter<'_>) -> fmt::Result {
let message = match self {
Self::DefaultStopwordDeletion => {
"default stopword deletion is not a valid method for repeated report language"
}
Self::InvalidDeletionPayload => "invalid stopword-deletion payload",
};
formatter.write_str(message)
}
}

impl std::error::Error for StopwordDeletionError {}

#[cfg(test)]
mod tests {
use super::StopwordDeletionError;

#[test]
fn error_messages_are_stable() {
for (error, message) in [
(
StopwordDeletionError::DefaultStopwordDeletion,
"default stopword deletion is not a valid method for repeated report language",
),
(
StopwordDeletionError::InvalidDeletionPayload,
"invalid stopword-deletion payload",
),
] {
assert_eq!(error.to_string(), message);
}
}
}
114 changes: 114 additions & 0 deletions crates/stopword_deletion/src/kind.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,114 @@
//! Deletion methods that cannot silently erase repeated report language.

use crate::StopwordDeletionError;

/// Closed vocabulary of deletion versus explicit method-source treatments.
#[derive(Clone, Copy, Debug, Eq, PartialEq)]
pub enum DeletionKind {
/// A default or global stopword list applied as deletion.
DefaultStopwordList,
/// Repeated language kept as explicit method/background structure.
ExplicitMethodSource,
}

impl DeletionKind {
/// Return the stable wire kind name.
#[must_use]
pub const fn wire_name(self) -> &'static str {
match self {
Self::DefaultStopwordList => "default_stopword_list",
Self::ExplicitMethodSource => "explicit_method_source",
}
}

/// Parse a stable wire kind name.
///
/// # Errors
///
/// Returns [`StopwordDeletionError::InvalidDeletionPayload`] for unrecognized
/// names.
pub fn from_wire_name(name: &str) -> Result<Self, StopwordDeletionError> {
match name {
"default_stopword_list" => Ok(Self::DefaultStopwordList),
"explicit_method_source" => Ok(Self::ExplicitMethodSource),
_ => Err(StopwordDeletionError::InvalidDeletionPayload),
}
}
}

/// Refuse to treat a default stopword list as a valid deletion method.
///
/// # Errors
///
/// Returns [`StopwordDeletionError::DefaultStopwordDeletion`] when `kind` is
/// [`DeletionKind::DefaultStopwordList`].
pub fn refuse_default_stopword_deletion(kind: DeletionKind) -> Result<(), StopwordDeletionError> {
match kind {
DeletionKind::DefaultStopwordList => Err(StopwordDeletionError::DefaultStopwordDeletion),
DeletionKind::ExplicitMethodSource => Ok(()),
}
}

/// Fraction of recovered deletion kinds that match known truth.
///
/// # Errors
///
/// Returns [`StopwordDeletionError::InvalidDeletionPayload`] when either slice
/// is empty or the lengths differ.
pub fn identity_recovery_rate(
truth: &[DeletionKind],
decided: &[DeletionKind],
) -> Result<f64, StopwordDeletionError> {
if truth.is_empty() || truth.len() != decided.len() {
return Err(StopwordDeletionError::InvalidDeletionPayload);
}
let mut matches = 0_u32;
for (truth_kind, decided_kind) in truth.iter().zip(decided) {
if truth_kind == decided_kind {
matches += 1;
}
}
Ok(f64::from(matches) / truth.len() as f64)
}

#[cfg(test)]
mod tests {
use super::{DeletionKind, identity_recovery_rate, refuse_default_stopword_deletion};
use crate::StopwordDeletionError;

#[test]
fn local_branches_cover_kinds_payloads_and_wire_names() {
assert_eq!(
refuse_default_stopword_deletion(DeletionKind::DefaultStopwordList),
Err(StopwordDeletionError::DefaultStopwordDeletion)
);
refuse_default_stopword_deletion(DeletionKind::ExplicitMethodSource).expect("source");
for kind in [
DeletionKind::DefaultStopwordList,
DeletionKind::ExplicitMethodSource,
] {
assert_eq!(
DeletionKind::from_wire_name(kind.wire_name()).expect("round-trip"),
kind
);
}
assert_eq!(
DeletionKind::from_wire_name("tfidf_weight"),
Err(StopwordDeletionError::InvalidDeletionPayload)
);
let matched = identity_recovery_rate(
&[DeletionKind::ExplicitMethodSource],
&[DeletionKind::ExplicitMethodSource],
)
.expect("rate");
assert!((matched - 1.0).abs() < f64::EPSILON);
assert_eq!(
identity_recovery_rate(&[], &[]),
Err(StopwordDeletionError::InvalidDeletionPayload)
);
assert_eq!(
identity_recovery_rate(&[DeletionKind::DefaultStopwordList], &[]),
Err(StopwordDeletionError::InvalidDeletionPayload)
);
}
}
20 changes: 20 additions & 0 deletions crates/stopword_deletion/src/lib.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
#![forbid(unsafe_code)]
#![deny(missing_docs)]
#![allow(clippy::cast_precision_loss)]
//! Default stopword deletion is not a valid method for repeated report language.
//!
//! A global stopword list cannot erase boilerplate. Repeated template, section,
//! copied-text, style, modality, and corpus-background wording stays explicit
//! method/background structure (ADR 0004/0012).

mod error;
mod kind;

/// Fail-closed stopword-deletion errors.
pub use error::StopwordDeletionError;
/// Closed vocabulary of deletion versus explicit method-source treatments.
pub use kind::DeletionKind;
/// Fraction of recovered deletion kinds that match known truth.
pub use kind::identity_recovery_rate;
/// Refuse to treat a default stopword list as a valid deletion method.
pub use kind::refuse_default_stopword_deletion;
7 changes: 7 additions & 0 deletions crates/stopword_deletion/tests/crate_contract.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
//! Integration contract for the `stopword_deletion` package identity.

#[test]
fn package_identity_is_stable() {
let observed = std::hint::black_box(env!("CARGO_PKG_NAME"));
assert_eq!(observed, "stopword_deletion");
}
64 changes: 64 additions & 0 deletions crates/stopword_deletion/tests/stopword_deletion_contract.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,64 @@
//! Default stopword deletion cannot erase repeated report language.

use stopword_deletion::{
DeletionKind, StopwordDeletionError, identity_recovery_rate, refuse_default_stopword_deletion,
};

#[test]
fn a_default_stopword_list_cannot_delete_repeated_report_language() {
assert_eq!(
refuse_default_stopword_deletion(DeletionKind::DefaultStopwordList),
Err(StopwordDeletionError::DefaultStopwordDeletion)
);
refuse_default_stopword_deletion(DeletionKind::ExplicitMethodSource).expect("source");
}

#[test]
fn recovered_kinds_match_known_truth_better_than_a_stopword_collapse() {
let truth = [
DeletionKind::ExplicitMethodSource,
DeletionKind::ExplicitMethodSource,
DeletionKind::DefaultStopwordList,
];
let recovered = truth;
let collapsed = [
DeletionKind::DefaultStopwordList,
DeletionKind::DefaultStopwordList,
DeletionKind::DefaultStopwordList,
];
let recovered_rate = identity_recovery_rate(&truth, &recovered).expect("recovered");
let collapsed_rate = identity_recovery_rate(&truth, &collapsed).expect("collapsed");
let expected = {
let mut matches = 0_u32;
for (truth_kind, decided_kind) in truth.iter().zip(recovered.iter()) {
if truth_kind == decided_kind {
matches += 1;
}
}
f64::from(matches) / f64::from(u32::try_from(truth.len()).expect("len"))
};
assert!((recovered_rate - expected).abs() < f64::EPSILON);
assert!(recovered_rate > collapsed_rate);
}

#[test]
fn empty_or_mismatched_kind_payloads_fail_closed() {
assert_eq!(
identity_recovery_rate(&[], &[]),
Err(StopwordDeletionError::InvalidDeletionPayload)
);
assert_eq!(
identity_recovery_rate(&[DeletionKind::DefaultStopwordList], &[]),
Err(StopwordDeletionError::InvalidDeletionPayload)
);
assert_eq!(
identity_recovery_rate(
&[
DeletionKind::DefaultStopwordList,
DeletionKind::ExplicitMethodSource
],
&[DeletionKind::DefaultStopwordList]
),
Err(StopwordDeletionError::InvalidDeletionPayload)
);
}
4 changes: 2 additions & 2 deletions docs/TRACEABILITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,8 +23,8 @@ The full APA 7th standards/literature register remains `docs/research/standards-
| immutable split/run/reproducibility manifests | ADR 0013; ERD | `tepp_api` reproducibility manifest and corpus-split leakage-audit wire (`CorpusSplitManifest` v1) on this PR; `persistence_postgres` append-only SQL insert/lookup for `reproducibility_manifest`, `corpus_split_manifest`, `model_run`, and `model_artifact` (migration `0003`); full physical ERD constraints remaining | partial |
| multilingual shared latent semantic space | PRD; ADR 0004 | future semantic/concept/topic crates | accepted-target |
| TRSL-TM temporal/relational topic posterior and backend compatibility | ADR 0012; ADR 0004 | future `topic_measurement` | accepted-target |
| global P0 topic identity with activity/dormancy/reactivation | ADR 0012 | `topic_lineage` activity/dormancy/reactivation identity on the active PR; birth/split/merge remaining | active-PR |
| no default stopword deletion / no TF-IDF-BM25 inferential weighting | ADR 0004/0012; PRD/TRD | future semantic/method-source model | accepted-target |
| global P0 topic identity with activity/dormancy/reactivation | ADR 0012 | future topic lineage/activity state | accepted-target |
| no default stopword deletion / no TF-IDF-BM25 inferential weighting | ADR 0004/0012; PRD/TRD | `stopword_deletion` default-list refusal on the active PR; TF-IDF/BM25 inferential-weight refusal remains accepted-target | partial |
| report template/section/copied/style/modality method effects | ADR 0004/0012; PRD/TRD | simulation truth factors implemented; estimator-side method model remains future | partial |
| candidate K statistical/Pareto gates + blinded LLM review | ADR 0012; research | future `model_selection` | accepted-target |
| compositional topic correlation / stable clustering | ADR 0005/0012; research | future `network_analysis` | accepted-target |
Expand Down
2 changes: 1 addition & 1 deletion docs/adr/0004-shared-multilingual-latent-space.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# ADR 0004 — Shared multilingual latent semantic space

**Decision status:** Accepted
**Implementation maturity:** accepted-target
**Implementation maturity:** partial — default stopword-deletion refusal is `stopword_deletion` on the active PR; shared-space estimators, language profiles, and TF-IDF/BM25 inferential-weight refusal remain accepted-target
**Date:** 2026-08-05
**Supersedes:** None. ADR 0012 governs the complete topic-estimator/backend/global-topic contract built on this multilingual measurement decision.

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
# ADR 0012 — Temporal Relational Shared-Latent Topic Measurement

**Decision status:** Accepted
**Implementation maturity:** partial — default stopword-deletion refusal is `stopword_deletion` on the active PR; topic estimator, global topic identity, method-effect model, and TF-IDF/BM25 inferential-weight refusal remain accepted-target
**Implementation maturity:** active-PR — `topic_lineage` keeps one P0 identity across active/dormant/reactivated states; remaining TRSL-TM estimator, method effects, and backend interchange remain accepted-target
**Implementation maturity:** active-PR — `network_analysis` refuses raw-simplex Euclidean geometry and scores cluster pair precision/recall; remaining TRSL-TM estimator, global topic identity, method effects, and backend interchange remain accepted-target
**Implementation maturity:** active-PR — `model_selection` statistical/Pareto candidate-`K` gates and known-`K` RMSE live in the new crate; remaining TRSL-TM estimator, global topic identity, method effects, and backend interchange remain accepted-target
Expand Down
Loading
Loading