Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -61,6 +61,7 @@ boundaries above remain the target modular MSA architecture.
| `tepp_simulation` | known-truth temporal/event data generation |
| `validation_core` | RMSE, bias, coverage, graph, and Monte Carlo metrics |
| `tepp_api` | versioned DTO, schema, and export contracts |
| `section_source` | report section boilerplate is not unique latent content and not stopword deletion |

No crate exposes placeholder production behavior in Task 1. This prevents an
empty façade from becoming a de facto public API before its invariants and tests
Expand Down
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ All notable changes to TEPP are documented here. The format follows Keep a Chang

### Added

- `section_source` method gate: report section boilerplate is not unique latent content and is not stopword deletion; recovered section kinds match known truth at a higher computed rate than collapsing every token to unique content (ADR 0004/0012).
- `tepp_api` naruon live loopback HTTP/1.1 listener: `serve_one` installs a read/write deadline, requires a loopback `Host`, refuses `Transfer-Encoding` and NIM/proxy credential headers, parses `knowledge_cutoff` as RFC 3339 and refuses a future cutoff, keys analysis-run idempotency by tenant plus key, and proves both analysis-run and export POSTs over a real `TcpStream`. Not a production TLS/`$PORT` service (ADR 0011).
- `tepp_api` adaptive orchestration router (ADR 0010): versioned `direct`/`verify`/`committee`/`conductor`/`abstain` selection from CPU `f64` risk, ambiguity, evidence, and token-budget inputs; recorded stages, recursion, decomposition, access lists, and role-specific reasoning effort; fail-closed document-controlled policy/access/credentials; LLM plans remain proposals under deterministic statistical authority; comparable-budget ablation requires a direct baseline; credential-free contextual-orchestrator binding. Live NIM HTTP remains accepted-target.
- `tepp_api` purpose-bound provider-payload minimization: time-bounded `PurposeGrant` evaluation, fail-closed expired/not-yet-valid/inverted/cross-tenant/impossible-calendar denial, semantic UTC calendar validation, refusal to copy identity mappings into model-provider payloads or ordinary logs, preservation of opaque analytical identifiers and membership roles (no blanket PII mask), a separately authorized scientific re-identification path, and an internally bound FIPS 180-4 SHA-256 audit digest appended through `ReidentificationAuditSink` before disclosure.
Expand Down
4 changes: 4 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 2 additions & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ members = [
"crates/tepp_simulation",
"crates/validation_core",
"crates/tepp_api",
"crates/section_source",
]
default-members = [
"crates/evidence_core",
Expand All @@ -23,6 +24,7 @@ default-members = [
"crates/tepp_simulation",
"crates/validation_core",
"crates/tepp_api",
"crates/section_source",
]

[workspace.package]
Expand Down
1 change: 1 addition & 0 deletions DOCUMENTATION.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,7 @@ TEPP's approved PRD v0.4 and implementation plan are the primary product baselin
| Actions fleet research doctoring | [`docs/research/actions-workflow-fleet.md`](docs/research/actions-workflow-fleet.md) |
| Retention/deletion/legal-hold doctoring | [`docs/research/retention-deletion-legal-hold.md`](docs/research/retention-deletion-legal-hold.md) |
| Provider-payload minimization doctoring | [`docs/research/provider-payload-minimization.md`](docs/research/provider-payload-minimization.md) |
| Section-source method-effect doctoring | [`docs/research/section-source.md`](docs/research/section-source.md) |
| Adaptive orchestration router doctoring | [`docs/research/adaptive-orchestration-router.md`](docs/research/adaptive-orchestration-router.md) |
| Hourly NIM OpenCode doctoring | [`docs/doctoring/hourly-nim-opencode-development.md`](docs/doctoring/hourly-nim-opencode-development.md) |
| Change history | [`CHANGELOG.md`](CHANGELOG.md) |
Expand Down
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,7 @@ crates/corpus_split
crates/tepp_simulation
crates/validation_core
crates/tepp_api
crates/section_source
```

## Local verification
Expand Down
17 changes: 17 additions & 0 deletions crates/section_source/Cargo.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
[package]
name = "section_source"
description = "Report section boilerplate is not unique latent content and not stopword deletion."
version.workspace = true
edition.workspace = true
rust-version.workspace = true
license.workspace = true
authors.workspace = true
repository.workspace = true
homepage.workspace = true
readme.workspace = true
keywords.workspace = true
categories.workspace = true
publish = false

[lints]
workspace = true
53 changes: 53 additions & 0 deletions crates/section_source/src/error.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
//! Fail-closed section-source errors.

use std::fmt;

/// A fail-closed section-source error.
#[derive(Clone, Copy, Debug, Eq, PartialEq)]
#[non_exhaustive]
pub enum SectionSourceError {
/// Section boilerplate was treated as unique latent content.
SectionIsNotUniqueContent,
/// Section boilerplate was treated as stopword deletion.
SectionIsNotStopwordDeletion,
/// A recovery slice was empty or length-mismatched.
InvalidSectionPayload,
}

impl fmt::Display for SectionSourceError {
fn fmt(&self, formatter: &mut fmt::Formatter<'_>) -> fmt::Result {
let message = match self {
Self::SectionIsNotUniqueContent => "section boilerplate is not unique latent content",
Self::SectionIsNotStopwordDeletion => "section boilerplate is not stopword deletion",
Self::InvalidSectionPayload => "invalid section-source payload",
};
formatter.write_str(message)
}
}

impl std::error::Error for SectionSourceError {}

#[cfg(test)]
mod tests {
use super::SectionSourceError;

#[test]
fn error_messages_are_stable() {
for (error, message) in [
(
SectionSourceError::SectionIsNotUniqueContent,
"section boilerplate is not unique latent content",
),
(
SectionSourceError::SectionIsNotStopwordDeletion,
"section boilerplate is not stopword deletion",
),
(
SectionSourceError::InvalidSectionPayload,
"invalid section-source payload",
),
] {
assert_eq!(error.to_string(), message);
}
}
}
132 changes: 132 additions & 0 deletions crates/section_source/src/kind.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,132 @@
//! Section boilerplate versus unique latent content.

use crate::SectionSourceError;

/// Closed vocabulary of section-related token treatments.
#[derive(Clone, Copy, Debug, Eq, PartialEq)]
pub enum SectionKind {
/// Repeated report section heading or boilerplate.
SectionBoilerplate,
/// Unique document content that is not section structure.
UniqueContent,
}

impl SectionKind {
/// Return the stable wire kind name.
#[must_use]
pub const fn wire_name(self) -> &'static str {
match self {
Self::SectionBoilerplate => "section_boilerplate",
Self::UniqueContent => "unique_content",
}
}

/// Parse a stable wire kind name.
///
/// # Errors
///
/// Returns [`SectionSourceError::InvalidSectionPayload`] for unrecognized
/// names.
pub fn from_wire_name(name: &str) -> Result<Self, SectionSourceError> {
match name {
"section_boilerplate" => Ok(Self::SectionBoilerplate),
"unique_content" => Ok(Self::UniqueContent),
_ => Err(SectionSourceError::InvalidSectionPayload),
}
}
}

/// Refuse to treat section boilerplate as unique latent content.
///
/// # Errors
///
/// Returns [`SectionSourceError::SectionIsNotUniqueContent`] when `kind` is
/// [`SectionKind::SectionBoilerplate`].
pub fn refuse_section_as_unique_content(kind: SectionKind) -> Result<(), SectionSourceError> {
match kind {
SectionKind::SectionBoilerplate => Err(SectionSourceError::SectionIsNotUniqueContent),
SectionKind::UniqueContent => Ok(()),
}
}

/// Refuse to treat section boilerplate as stopword deletion.
///
/// # Errors
///
/// Returns [`SectionSourceError::SectionIsNotStopwordDeletion`] when `kind` is
/// [`SectionKind::SectionBoilerplate`].
pub fn refuse_section_as_stopword_deletion(kind: SectionKind) -> Result<(), SectionSourceError> {
match kind {
SectionKind::SectionBoilerplate => Err(SectionSourceError::SectionIsNotStopwordDeletion),
SectionKind::UniqueContent => Ok(()),
}
}

/// Fraction of recovered section kinds that match known truth.
///
/// # Errors
///
/// Returns [`SectionSourceError::InvalidSectionPayload`] when either slice is
/// empty or the lengths differ.
pub fn identity_recovery_rate(
truth: &[SectionKind],
decided: &[SectionKind],
) -> Result<f64, SectionSourceError> {
if truth.is_empty() || truth.len() != decided.len() {
return Err(SectionSourceError::InvalidSectionPayload);
}
let mut matches = 0_u32;
for (truth_kind, decided_kind) in truth.iter().zip(decided) {
if truth_kind == decided_kind {
matches += 1;
}
}
Ok(f64::from(matches) / truth.len() as f64)
}

#[cfg(test)]
mod tests {
use super::{
SectionKind, identity_recovery_rate, refuse_section_as_stopword_deletion,
refuse_section_as_unique_content,
};
use crate::SectionSourceError;

#[test]
fn local_branches_cover_kinds_payloads_and_wire_names() {
assert_eq!(
refuse_section_as_unique_content(SectionKind::SectionBoilerplate),
Err(SectionSourceError::SectionIsNotUniqueContent)
);
assert_eq!(
refuse_section_as_stopword_deletion(SectionKind::SectionBoilerplate),
Err(SectionSourceError::SectionIsNotStopwordDeletion)
);
refuse_section_as_unique_content(SectionKind::UniqueContent).expect("unique");
refuse_section_as_stopword_deletion(SectionKind::UniqueContent).expect("unique");
for kind in [SectionKind::SectionBoilerplate, SectionKind::UniqueContent] {
assert_eq!(
SectionKind::from_wire_name(kind.wire_name()).expect("round-trip"),
kind
);
}
assert_eq!(
SectionKind::from_wire_name("template_source"),
Err(SectionSourceError::InvalidSectionPayload)
);
let matched = identity_recovery_rate(
&[SectionKind::SectionBoilerplate],
&[SectionKind::SectionBoilerplate],
)
.expect("rate");
assert!((matched - 1.0).abs() < f64::EPSILON);
assert_eq!(
identity_recovery_rate(&[], &[]),
Err(SectionSourceError::InvalidSectionPayload)
);
assert_eq!(
identity_recovery_rate(&[SectionKind::SectionBoilerplate], &[]),
Err(SectionSourceError::InvalidSectionPayload)
);
}
}
22 changes: 22 additions & 0 deletions crates/section_source/src/lib.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
#![forbid(unsafe_code)]
#![deny(missing_docs)]
#![allow(clippy::cast_precision_loss)]
//! Report section boilerplate is not unique latent content.
//!
//! Repeated section headings stay explicit method/background structure. They
//! are not unique document meaning and are not erased by a stopword list
//! (ADR 0004/0012).

mod error;
mod kind;

/// Fail-closed section-source errors.
pub use error::SectionSourceError;
/// Closed vocabulary of section-related token treatments.
pub use kind::SectionKind;
/// Fraction of recovered section kinds that match known truth.
pub use kind::identity_recovery_rate;
/// Refuse to treat section boilerplate as stopword deletion.
pub use kind::refuse_section_as_stopword_deletion;
/// Refuse to treat section boilerplate as unique latent content.
pub use kind::refuse_section_as_unique_content;
7 changes: 7 additions & 0 deletions crates/section_source/tests/crate_contract.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
//! Integration contract for the `section_source` package identity.

#[test]
fn package_identity_is_stable() {
let observed = std::hint::black_box(env!("CARGO_PKG_NAME"));
assert_eq!(observed, "section_source");
}
67 changes: 67 additions & 0 deletions crates/section_source/tests/section_source_contract.rs
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
//! Report section boilerplate is not unique content and not stopword deletion.

use section_source::{
SectionKind, SectionSourceError, identity_recovery_rate, refuse_section_as_stopword_deletion,
refuse_section_as_unique_content,
};

#[test]
fn a_section_cannot_become_unique_content_or_stopword_deletion() {
assert_eq!(
refuse_section_as_unique_content(SectionKind::SectionBoilerplate),
Err(SectionSourceError::SectionIsNotUniqueContent)
);
assert_eq!(
refuse_section_as_stopword_deletion(SectionKind::SectionBoilerplate),
Err(SectionSourceError::SectionIsNotStopwordDeletion)
);
refuse_section_as_unique_content(SectionKind::UniqueContent).expect("unique");
refuse_section_as_stopword_deletion(SectionKind::UniqueContent).expect("unique");
}

#[test]
fn recovered_kinds_match_known_truth_better_than_a_unique_collapse() {
let truth = [
SectionKind::SectionBoilerplate,
SectionKind::UniqueContent,
SectionKind::SectionBoilerplate,
];
let recovered = truth;
let collapsed = [
SectionKind::UniqueContent,
SectionKind::UniqueContent,
SectionKind::UniqueContent,
];
let recovered_rate = identity_recovery_rate(&truth, &recovered).expect("recovered");
let collapsed_rate = identity_recovery_rate(&truth, &collapsed).expect("collapsed");
let expected = {
let mut matches = 0_u32;
for (truth_kind, decided_kind) in truth.iter().zip(recovered.iter()) {
if truth_kind == decided_kind {
matches += 1;
}
}
f64::from(matches) / f64::from(u32::try_from(truth.len()).expect("len"))
};
assert!((recovered_rate - expected).abs() < f64::EPSILON);
assert!(recovered_rate > collapsed_rate);
}

#[test]
fn empty_or_mismatched_kind_payloads_fail_closed() {
assert_eq!(
identity_recovery_rate(&[], &[]),
Err(SectionSourceError::InvalidSectionPayload)
);
assert_eq!(
identity_recovery_rate(&[SectionKind::SectionBoilerplate], &[]),
Err(SectionSourceError::InvalidSectionPayload)
);
assert_eq!(
identity_recovery_rate(
&[SectionKind::SectionBoilerplate, SectionKind::UniqueContent],
&[SectionKind::SectionBoilerplate]
),
Err(SectionSourceError::InvalidSectionPayload)
);
}
2 changes: 1 addition & 1 deletion docs/TRACEABILITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ The full APA 7th standards/literature register remains `docs/research/standards-
| TRSL-TM temporal/relational topic posterior and backend compatibility | ADR 0012; ADR 0004 | future `topic_measurement` | accepted-target |
| global P0 topic identity with activity/dormancy/reactivation | ADR 0012 | future topic lineage/activity state | accepted-target |
| no default stopword deletion / no TF-IDF-BM25 inferential weighting | ADR 0004/0012; PRD/TRD | future semantic/method-source model | accepted-target |
| report template/section/copied/style/modality method effects | ADR 0004/0012; PRD/TRD | simulation truth factors implemented; estimator-side method model remains future | partial |
| report template/section/copied/style/modality method effects | ADR 0004/0012; PRD/TRD | `section_source` section-boilerplate gate on the active PR; remaining template/copied/style/modality estimator-side model remains future | partial |
| candidate K statistical/Pareto gates + blinded LLM review | ADR 0012; research | future `model_selection` | accepted-target |
| compositional topic correlation / stable clustering | ADR 0005/0012; research | future `network_analysis` | accepted-target |
| posterior ESEM / longitudinal invariance / DSEM | ADR 0005 | future `psychometric_core` | accepted-target |
Expand Down
2 changes: 1 addition & 1 deletion docs/adr/0004-shared-multilingual-latent-space.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# ADR 0004 — Shared multilingual latent semantic space

**Decision status:** Accepted
**Implementation maturity:** accepted-target
**Implementation maturity:** partial — section-boilerplate method source is `section_source` on the active PR; shared-space estimators, language profiles, stopword-deletion and TF-IDF/BM25 inferential-weight refusal remain accepted-target
**Date:** 2026-08-05
**Supersedes:** None. ADR 0012 governs the complete topic-estimator/backend/global-topic contract built on this multilingual measurement decision.

Expand Down
2 changes: 1 addition & 1 deletion docs/adr/0011-standalone-modular-msa-boundary.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# ADR 0011 — Standalone operation and modular CWL MSA boundary

**Decision status:** Accepted
**Implementation maturity:** partial — Rust crates are independently usable; naruon HTTP interchange and loopback live listener (`POST /v1/analysis-runs` and `/v1/exports`, fail-closed table-access, NIM/proxy headers, RFC 3339 cutoff, stream deadline) are on the active PR (not implemented-main); production TLS/`$PORT` and remaining persistence integrations remain accepted-target
**Implementation maturity:** partial — Rust crates are independently usable; naruon HTTP interchange and loopback live listener (`POST /v1/analysis-runs` and `/v1/exports`, fail-closed table-access, NIM/proxy headers, RFC 3339 cutoff, stream deadline) are on the active PR (not implemented-main); production TLS/`$PORT` and remaining persistence integrations remain accepted-target
**Date:** 2026-08-10
**Supersedes:** The broad cross-service ownership wording in ADR 0001. ADR 0001 remains authoritative for Rust-first numerical architecture.

Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# ADR 0012 — Temporal Relational Shared-Latent Topic Measurement

**Decision status:** Accepted
**Implementation maturity:** accepted-target
**Implementation maturity:** partial — section-boilerplate method source is `section_source` on the active PR; topic estimator, global topic identity, remaining method-effect model, and TF-IDF/BM25 inferential-weight refusal remain accepted-target
**Date:** 2026-08-12
**Supersedes:** None; refines ADR 0004 and ADR 0005 without replacing their multilingual and psychometric authorities.

Expand Down
Loading
Loading