Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
143 commits
Select commit Hold shift + click to select a range
56950cf
feat(model): statistical Pareto K gates refuse LLM numerical authority
seonghobae Aug 13, 2026
573f604
feat(topic): keep one identity across dormancy and reactivation
seonghobae Aug 13, 2026
43f9c9e
feat(api): serve naruon POSTs on loopback with a live deadline
cursoragent Aug 16, 2026
6a6ce0c
test(api): reproduce missing LineageWeave consumer contract
seonghobae Aug 19, 2026
036e549
feat(api): admit LineageWeave on the modular run boundary
seonghobae Aug 19, 2026
55efc13
ci: stage LineageWeave contract formatting repair
seonghobae Aug 19, 2026
afce9b6
fix(api): format and compile the LineageWeave contract
Aug 19, 2026
a3c57a9
feat(api): publish terminal analysis result contract
seonghobae Aug 20, 2026
003dae3
fix(api): preserve existing contract documentation
seonghobae Aug 20, 2026
0cb693f
fix(api): restore strict terminal result implementation
seonghobae Aug 20, 2026
cffbf4e
test(api): cover terminal analysis result contract
seonghobae Aug 20, 2026
16de7b0
test(api): require cutoff-safe LineageWeave project history
seonghobae Aug 20, 2026
803a8e7
feat(api): expose cutoff-safe project history contracts
seonghobae Aug 20, 2026
b8c79be
feat(api): add cutoff-safe project history projection
seonghobae Aug 20, 2026
e881949
feat(api): publish the LineageWeave project history exchange
seonghobae Aug 20, 2026
c172b00
ci: materialize the PR 159 availability-clock repair
seonghobae Aug 20, 2026
b1571e5
ci: verify and publish the project-history availability contract
seonghobae Aug 20, 2026
6c89219
ci: verify TEPP LineageWeave project-history contract
seonghobae Aug 20, 2026
24f00c0
feat(api): add analysis run status contract
seonghobae Aug 20, 2026
0cacdff
fix(api): declare temporal core workspace version
seonghobae Aug 20, 2026
b648e7c
fix(api): align project-history clocks and non-causal evidence
seonghobae Aug 20, 2026
30918e5
fix(api): harden analysis result serialization bindings
seonghobae Aug 20, 2026
760ac3b
Merge remote-tracking branch 'origin/main' into fix/pr-107-naruon-live
seonghobae Aug 20, 2026
0e10662
Merge #107 live listener base into consumer contract
seonghobae Aug 20, 2026
a707130
docs(adr): record consumer-scoped analysis-run ingress
seonghobae Aug 20, 2026
c255ac3
docs(adr): index modular consumer ingress
seonghobae Aug 20, 2026
bddb105
Merge consumer contract base updates
seonghobae Aug 20, 2026
91fba35
Merge branch 'feat/lineageweave-live-consumer-contract' of https://gi…
seonghobae Aug 20, 2026
262f841
test(api): require live project-history service route
seonghobae Aug 20, 2026
ee3e941
ci: prove and implement the live project-history route
seonghobae Aug 20, 2026
de38550
fix(api): validate localhost ports in live host checks
seonghobae Aug 20, 2026
64818cf
fix(api): share strict loopback host validation
seonghobae Aug 20, 2026
3b1b8be
fix(api): satisfy strict contract lint
seonghobae Aug 20, 2026
ca363be
Merge remote-tracking branch 'origin/feat/lineageweave-live-consumer-…
seonghobae Aug 20, 2026
a9bd157
fix(ci): align the TEPP history repair with the live contract
seonghobae Aug 20, 2026
d0967f3
fix(ci): make the TEPP live-route repair exact-head compatible
seonghobae Aug 20, 2026
67ef83a
fix(ci): install pinned Rust components correctly
seonghobae Aug 20, 2026
542b96c
test(api): complete naruon live branch coverage
seonghobae Aug 20, 2026
9ea0c39
fix(ci): remove the superseded analysis-run body-limit import
seonghobae Aug 20, 2026
2342d5f
ci: remove superseded PR 159 verification workflow
seonghobae Aug 20, 2026
b8cfeb6
test(api): close project-history line and branch coverage gaps
seonghobae Aug 20, 2026
950f757
ci: verify the TEPP history coverage contract before publish
seonghobae Aug 20, 2026
6037713
chore: close accidental placeholder issue
seonghobae Aug 20, 2026
ae49187
chore: remove accidental placeholder cleanup workflow
seonghobae Aug 20, 2026
13e17d0
test(api): close analysis-run live coverage gaps
seonghobae Aug 20, 2026
9786aff
chore(ci): remove completed project-history repair workflow
seonghobae Aug 20, 2026
d048e92
test(coverage): merge branch outcomes by source coordinate
seonghobae Aug 20, 2026
378dc8f
ci: finalize TEPP project-history contract
seonghobae Aug 20, 2026
0e29108
test(api): close analysis-run live coverage gaps
seonghobae Aug 20, 2026
2454966
ci: pin project history verification actions
seonghobae Aug 20, 2026
3791284
Merge branch 'feat/lineageweave-project-history-projection' of https:…
seonghobae Aug 20, 2026
f99dc56
ci: pin finalization workflow actions
seonghobae Aug 20, 2026
02339a5
Merge remote-tracking branch 'origin/feat/lineageweave-live-consumer-…
seonghobae Aug 20, 2026
41f02c8
ci: pin and rerun TEPP project-history finalization
seonghobae Aug 20, 2026
1e42d95
ci: dispatch pinned PR 159 finalizer
seonghobae Aug 20, 2026
ae18ae8
test(api): close project-history coverage edges
seonghobae Aug 20, 2026
1478708
Merge remote-tracking branch 'origin/feat/lineageweave-project-histor…
seonghobae Aug 20, 2026
2875431
ci: remove completed project-history finalizers
seonghobae Aug 20, 2026
5295f5e
docs: doctor the LineageWeave project-history contract
seonghobae Aug 20, 2026
a6cea38
test(api): reproduce idempotency delimiter collision
seonghobae Aug 20, 2026
814d2a4
fix(api): reject control characters in wire identities
seonghobae Aug 20, 2026
0ae6192
test(api): preserve multiline wire text
seonghobae Aug 20, 2026
020c353
fix(api): bound accepted analysis run payloads
seonghobae Aug 20, 2026
542fa0a
test(api): align control character contract
seonghobae Aug 20, 2026
586cda5
test: close project history coverage gaps
seonghobae Aug 20, 2026
f1c94f7
fix: validate terminal result bindings
seonghobae Aug 20, 2026
7ff6ae8
Merge remote-tracking branch 'origin/main' into integrate-pr67-main
seonghobae Aug 20, 2026
a88b66b
test(topic): use independent identity recovery oracle
seonghobae Aug 20, 2026
c0a1fe4
Merge remote-tracking branch 'origin/main' into HEAD
seonghobae Aug 20, 2026
a18076d
fix(api): revalidate project history projections
seonghobae Aug 20, 2026
fb783f5
test(api): cover empty https origin
seonghobae Aug 20, 2026
0cb9ff6
test(api): close unreachable HTTP branch
seonghobae Aug 20, 2026
f0b69bd
test(api): cover localhost live host acceptance
seonghobae Aug 20, 2026
07bb21f
test(api): close naruon HTTP branch coverage gap
seonghobae Aug 20, 2026
a1f7ca3
test(api): close project history coverage gaps
seonghobae Aug 20, 2026
d40b0a0
test(api): cover project history invariants
seonghobae Aug 20, 2026
c8d2a5b
test(api): cover project history response invariants
seonghobae Aug 20, 2026
2e592d6
Merge remote-tracking branch 'refs/remotes/origin/feat/lineageweave-p…
seonghobae Aug 20, 2026
855c6c7
test(api): remove timing-sensitive timeout assertion
seonghobae Aug 20, 2026
054f190
test(topic-lineage): complete identity branch contracts
seonghobae Aug 20, 2026
d735177
test(model-selection): complete pareto gate coverage
seonghobae Aug 20, 2026
ffbf50e
ci: restack LineageWeave consumer contract on merged ingress
seonghobae Aug 21, 2026
1fa8e9e
Merge main into completed analysis result contract
seonghobae Aug 21, 2026
63a419e
fix(docs): align naruon maturity with protected main
seonghobae Aug 21, 2026
4893a7e
ci: trigger LineageWeave consumer restack from PR
seonghobae Aug 21, 2026
11cc811
merge main into topic activity lineage
seonghobae Aug 21, 2026
191f14b
Merge origin/main into PR #67
seonghobae Aug 21, 2026
054b009
Merge remote-tracking branch 'origin/main' into HEAD
seonghobae Aug 21, 2026
3afeeb7
fix(api): complete lineageweave restack safely
seonghobae Aug 21, 2026
17f06e8
fix(api): resolve consumer-base host validation
seonghobae Aug 21, 2026
cbb3dc0
docs: bind consumer ingress to merged main lineage
seonghobae Aug 21, 2026
c9103d1
merge: restack project history on current consumer ingress
seonghobae Aug 21, 2026
21de05d
ci: verify and repair PR 155 review findings
seonghobae Aug 21, 2026
d54ba82
test: stage PR 155 review-finding repair
seonghobae Aug 21, 2026
0de7970
ci: execute the PR 155 repair through a recognized workflow
seonghobae Aug 21, 2026
fbb55f8
test: stage PR 159 timeout contract repair
seonghobae Aug 21, 2026
e5575a0
ci: verify PR 159 loopback timeout contract
seonghobae Aug 21, 2026
5d19407
fix: close PR 155 review findings
seonghobae Aug 21, 2026
19ce074
fix: complete PR 155 coverage gates
seonghobae Aug 21, 2026
6cc00f8
test: strengthen coverage report regressions
seonghobae Aug 21, 2026
7625dc6
fix(api): harden accepted receipts and provider headers
seonghobae Aug 21, 2026
b207234
fix(ci): keep timeout verification in committed tests
seonghobae Aug 21, 2026
512cbfe
Merge commit '6cc00f81b7f1998312fd7b8326d89f010d19d0b5' into review/p…
seonghobae Aug 21, 2026
5308507
Remove unreachable project history host branch
seonghobae Aug 21, 2026
116072a
fix: enforce project history response size symmetry
seonghobae Aug 21, 2026
9e583d1
docs: record project history service boundary
seonghobae Aug 21, 2026
1ce983e
docs: remove ADR trailing whitespace
seonghobae Aug 21, 2026
6852e9d
fix: harden analysis result contract boundaries
seonghobae Aug 21, 2026
38a0e98
fix: enforce strict project history timestamps
seonghobae Aug 21, 2026
b745ed4
docs: keep ADR index wording current
seonghobae Aug 21, 2026
95add88
test: close coverage and match guarded arms
seonghobae Aug 21, 2026
e3770a6
test: cover provider credential header branches
seonghobae Aug 21, 2026
910a54e
fix(api): reject delimiter-free credential headers
seonghobae Aug 21, 2026
efd5386
test: configure repository root for pytest
seonghobae Aug 21, 2026
48643e5
fix(coverage): preserve multiline match guards
seonghobae Aug 21, 2026
8e96984
Merge remote-tracking branch 'origin/feat/completed-analysis-result-c…
seonghobae Aug 21, 2026
a9a49d3
fix(coverage): respect match arm boundaries
seonghobae Aug 21, 2026
ef45763
fix(coverage): reject block-boundary false guards
seonghobae Aug 21, 2026
3b07002
fix coverage guard after destructuring match arm
seonghobae Aug 21, 2026
9238c3a
cover nested and long match guards
seonghobae Aug 21, 2026
e06e504
cover split nested match guard
seonghobae Aug 21, 2026
12ada13
retain guards after sibling match arms
seonghobae Aug 21, 2026
bc68cdc
style(api): apply rustfmt to project history tests
seonghobae Aug 21, 2026
7e32f50
fix(api): close project history live ingress gaps
seonghobae Aug 21, 2026
b3854db
test(model-selection): validate repeated truth recovery
seonghobae Aug 21, 2026
45b272d
fix(model-selection): validate llm candidate K
seonghobae Aug 21, 2026
b6102fd
feat(api): expose temporal evidence context for LineageWeave Ask (#158)
seonghobae Aug 22, 2026
c630bf2
Merge feat/lineageweave-project-history-projection into feat/lineagew…
seonghobae Aug 22, 2026
cce90a1
feat(engine): execute cutoff-safe analysis runs (#178)
seonghobae Aug 22, 2026
086a64d
docs: align LineageWeave wire evidence
seonghobae Aug 23, 2026
18c0fcd
fix(api): bound temporal context serialization
seonghobae Aug 23, 2026
bafd251
fix(api): bound serialization before allocation
seonghobae Aug 23, 2026
02c009c
feat(api): package loopback temporal context service (#186)
seonghobae Aug 23, 2026
49bf2ea
Merge commit 'refs/codex/pr67-head' into feat/trsl-topic-estimator-pr…
seonghobae Aug 23, 2026
195f18b
Merge commit 'refs/codex/pr73-head' into feat/trsl-topic-estimator-pr…
seonghobae Aug 23, 2026
17e9005
feat(topic): add bounded TRSL reference estimator
seonghobae Aug 23, 2026
ab2559e
merge: reconcile current PR 48 exact head
seonghobae Aug 23, 2026
228a8c1
merge: compose LineageWeave consumer contract stack
seonghobae Aug 23, 2026
6ddff63
merge: compose terminal analysis result contract
seonghobae Aug 23, 2026
c0339f9
feat(analysis): publish topic lineage artifacts
seonghobae Aug 23, 2026
eb06114
Merge remote-tracking branch 'origin/agent/topic-logratio-coordinates…
seonghobae Aug 23, 2026
1c5480c
Merge remote-tracking branch 'origin/agent/topic-logratio-coordinates…
seonghobae Aug 23, 2026
d894705
fix(deps): version topic workspace paths
seonghobae Aug 23, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
.codegraph
.git
node_modules
target
6 changes: 3 additions & 3 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -223,7 +223,7 @@ jobs:
with:
persist-credentials: false
- name: Install pinned nightly with LLVM tools
run: rustup toolchain install nightly-2026-08-01 --profile minimal --component llvm-tools-preview
run: rustup toolchain install nightly-2026-08-21 --profile minimal --component llvm-tools-preview
- name: Restore pinned cargo-llvm-cov
id: llvm-cov-cache
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
Expand All @@ -237,12 +237,12 @@ jobs:
run: cargo llvm-cov --version | grep -F "$CARGO_LLVM_COV_VERSION"
- name: Generate exact branch coverage
id: branch-report
run: cargo +nightly-2026-08-01 llvm-cov --branch --workspace --all-features --json --summary-only --output-path coverage-branches.json --ignore-filename-regex 'sqlx_live\.rs'
run: cargo +nightly-2026-08-21 llvm-cov --branch --workspace --all-features --json --output-path coverage-branches.json --ignore-filename-regex 'sqlx_live\.rs'
- name: Enforce complete branch coverage
run: python3 scripts/check_coverage.py coverage-branches.json --kind branches
- name: Show exact missing branch diagnostics
if: ${{ failure() && steps.branch-report.outcome == 'success' }}
run: cargo +nightly-2026-08-01 llvm-cov report --branch --text --show-missing-lines
run: cargo +nightly-2026-08-21 llvm-cov report --branch --text --show-missing-lines
- name: Upload exact branch coverage diagnostics
if: ${{ failure() && steps.branch-report.outcome == 'success' }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/hourly-nim-product-development.yml
Original file line number Diff line number Diff line change
Expand Up @@ -408,7 +408,7 @@ jobs:
if [ "${{ steps.llvm-cov-cache.outputs.cache-hit }}" != true ]; then
cargo install cargo-llvm-cov --locked --version 0.8.6
fi
rustup toolchain install nightly-2026-08-01 --profile minimal --component llvm-tools-preview
rustup toolchain install nightly-2026-08-21 --profile minimal --component llvm-tools-preview

- name: Run every release-quality gate
env:
Expand Down Expand Up @@ -437,9 +437,9 @@ jobs:
cargo deny check
line_coverage="$RUNNER_TEMP/coverage.lcov"
branch_coverage="$RUNNER_TEMP/coverage-branches.json"
cargo llvm-cov --workspace --all-features --lcov --output-path "$line_coverage"
cargo llvm-cov --workspace --all-features --lcov --output-path "$line_coverage" --ignore-filename-regex 'sqlx_live\.rs'
python3 scripts/check_coverage.py "$line_coverage" --kind lines --format lcov
cargo +nightly-2026-08-01 llvm-cov --branch --workspace --all-features --json --summary-only --output-path "$branch_coverage"
cargo +nightly-2026-08-21 llvm-cov --branch --workspace --all-features --json --output-path "$branch_coverage" --ignore-filename-regex 'sqlx_live\.rs'
python3 scripts/check_coverage.py "$branch_coverage" --kind branches
[ -z "$(git diff --name-only)" ]
[ -z "$(git ls-files --others --exclude-standard)" ]
Expand Down
10 changes: 9 additions & 1 deletion ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,6 +43,11 @@ flowchart LR

Every boundary must be independently usable and expose versioned contracts for integration with organization repositories, `naruon`, and `contextual-orchestrator`.

The `analysis_engine` vertical slice is intentionally separate from `tepp_api`:
the API owns wire contracts while the engine owns deterministic execution. It
does not replace the future topic or psychometric estimators and does not read
another service's application tables.

## Implemented foundation topology

Task 1 materializes the first storage-independent workspace boundaries. The
Expand All @@ -60,8 +65,11 @@ boundaries above remain the target modular MSA architecture.
| `corpus_split` | cutoff-safe, relation-aware partitioning |
| `tepp_simulation` | known-truth temporal/event data generation |
| `validation_core` | RMSE, bias, coverage, graph, and Monte Carlo metrics |
| `tepp_api` | versioned DTO, schema, and export contracts |
| `tepp_api` | versioned DTO, schema, terminal-result, and export contracts |
| `topic_measurement` | logistic-normal ALR and sequential Egozcue ILR topic coordinates |
| `model_selection` | statistical/Pareto candidate-`K` gates; LLM votes are not numerical authority |
| `topic_lineage` | global topic identity across active/dormant/reactivated states |
| `analysis_engine` | bounded cutoff-safe temporal evidence readiness execution and digest-bound terminal artifacts |

No crate exposes placeholder production behavior in Task 1. This prevents an
empty façade from becoming a de facto public API before its invariants and tests
Expand Down
7 changes: 7 additions & 0 deletions CHANGELOG.d/lineageweave-project-history.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# LineageWeave project-history projection

- `tepp_api` projects already-authorized LineageWeave evidence into a strict, cutoff-safe project history, preserves explicit source-event identities, validates deterministic chronological ordering, recomputes non-causal findings, and rejects fabricated, credential-bearing, or oversized payloads.
- Request and generated-projection serialization now share the 256 KiB wire limit, preventing a successful projection that cannot pass TEPP's own response parser.
- ADR 0019 records the credential-free bounded service boundary and its split of authorization (LineageWeave) from temporal projection (TEPP).
- This fragment preserves the child release note while the stacked branch retains the parent consumer-ingress changelog during the ordinary parent merge.
- The loopback timeout regression is now asserted in the committed Rust test; documentation CI is read-only and no longer mutates contributor branches.
3 changes: 3 additions & 0 deletions CHANGELOG.d/lineageweave-temporal-context-service.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
### Added

- Package the existing cutoff-safe `POST /v1/temporal-context` contract as the loopback-only `tepp-loopback` binary and container for trusted same-host consumers such as LineageWeave.
37 changes: 35 additions & 2 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,15 +6,31 @@ All notable changes to TEPP are documented here. The format follows Keep a Chang

### Added

- `topic_measurement` bounded deterministic CPU `f64` TRSL-TM reference estimator: canonical CSR/CSC inputs, cutoff-safe documents, standardized event time, weighted multiple memberships, prevalence covariates, explicit predecessor/successor regularization, multi-seed generalized EM, diagonal Laplace uncertainty, and fitted topic-lineage counts with known-truth RMSE plus exact line/branch coverage (ADR 0012; no persistence or accelerated-backend claim).
- `topic_measurement` logistic-normal additive log-ratio and sequential Egozcue isometric log-ratio coordinates: fail-closed simplex validation, max-shifted stable ALR/ILR inverses with true-parameter RMSE, pairwise CLR Aitchison distance recovered by ILR Euclidean isometry for valid composition pairs, and refusal of TF-IDF/BM25/keyword scores as inferential topic coordinates (ADR 0012 first production slice; no new migration).
- Coverage contract now excludes Rust multiline string continuation records emitted by LLVM LCOV, keeping the 100% authored-line gate focused on executable production lines.
- Coverage source classification now scans Rust normal/raw/byte strings, comments, and character literals with escape-aware state, preserving executable string method calls and ignoring quoted comments.
- `model_selection` candidate-`K` gates: statistical candidates require `K >= 2` and finite held-out log-likelihood/complexity, a Pareto front excludes dominated alternatives, LLM votes cannot define the numerical optimum, and selected `K` recovers known truth with computed RMSE.
- `topic_lineage` global P0 topic identity: activity may become dormant or reactivated without minting a new identity, and recovered identities match known truth at a higher computed rate than mint-on-reactivate replacements.
- `tepp_api` LineageWeave temporal-context contract (v1): cutoff-safe event eligibility, deterministic event-time ordering, explicit non-causal association/gap boundaries, HTTPS interchange construction, and loopback listener handling at `POST /v1/temporal-context`; read-only context requests no longer require the write-only idempotency header, and no causal inference or completed-result service is included.
- `tepp_api` LineageWeave consumer-scoped analysis-run ingress: versioned, credential-free requests use a published consumer identity and isolate idempotency by consumer, tenant workspace, and opaque caller key; the one-shot restack workflow is removed after the protected-main merge is verified.
- ADR 0017 records the consumer-scoped analysis-run ingress, its in-memory loopback maturity, and the persistence boundary required before production use.
- ADR 0019 records the credential-free bounded LineageWeave project-history service boundary and keeps source authorization with LineageWeave while TEPP owns temporal validation and deterministic projection.
- `tepp_api` project-history wire-size symmetry (ADR 0018): request and projection serialization enforce the shared 256 KiB limit, and generated projections fail closed before returning when their deterministic response would exceed it.
- Registered the analysis-engine gap-closure doctoring in the canonical documentation map so its product and scientific traceability record is discoverable.
- Authored Rust coverage classification now ignores standalone structural closing parentheses, preventing formatting-only LCOV rows from appearing as uncovered production behavior.
- `analysis_engine` vertical slice (ADR 0020): bounded Rust execution from an accepted analysis run to either a cutoff-safe readiness result or a validated `tepp.trsl_topic_lineage.v1` artifact from the ADR-0012 estimator. Topic artifacts preserve fitted predecessor/successor edges, connectable-post and lineage counts, request/snapshot/cutoff bindings, SHA-256 identity, and fail-closed non-convergence/tamper behavior with exact line/branch coverage. This remains active-PR evidence and does not claim causal or psychometric authority.
- Coverage classification preserves the final expression line of multiline Rust `match` guards while respecting preceding-arm boundaries, keeping the 100% authored-line gate conservative.
- `tepp_api` fail-closed analysis-result boundaries: status constructors reject
terminal envelopes that cannot fit the default 64 KiB status limit, and
standalone terminal results reject knowledge cutoffs in the future.
- `tepp_api` request-bound terminal analysis results and typed analysis-run status/read responses: accepted/running states cannot carry measurement evidence, terminal results bind exact request and receipt identities, and succeeded/failed payloads remain digest-bound or content-redacted.
- `tepp_api` naruon live loopback HTTP/1.1 listener: `serve_one` installs a read/write deadline, requires a loopback `Host`, refuses `Transfer-Encoding` and NIM/proxy credential headers, parses `knowledge_cutoff` as RFC 3339 and refuses a future cutoff, keys analysis-run idempotency by tenant plus key, and proves both analysis-run and export POSTs over a real `TcpStream`. Not a production TLS/`$PORT` service (ADR 0011).
- `tepp_api` adaptive orchestration router (ADR 0010): versioned `direct`/`verify`/`committee`/`conductor`/`abstain` selection from CPU `f64` risk, ambiguity, evidence, and token-budget inputs; recorded stages, recursion, decomposition, access lists, and role-specific reasoning effort; fail-closed document-controlled policy/access/credentials; LLM plans remain proposals under deterministic statistical authority; comparable-budget ablation requires a direct baseline; credential-free contextual-orchestrator binding. Live NIM HTTP remains accepted-target.
- `tepp_api` purpose-bound provider-payload minimization: time-bounded `PurposeGrant` evaluation, fail-closed expired/not-yet-valid/inverted/cross-tenant/impossible-calendar denial, semantic UTC calendar validation, refusal to copy identity mappings into model-provider payloads or ordinary logs, preservation of opaque analytical identifiers and membership roles (no blanket PII mask), a separately authorized scientific re-identification path, and an internally bound FIPS 180-4 SHA-256 audit digest appended through `ReidentificationAuditSink` before disclosure.
- `persistence_postgres` backup/restore integrity: restored snapshots stay unusable until tenant, canonical `SHA-256`, knowledge-cutoff eligibility, temporal window order, and append-only triggers revalidate; SQL probes raise `restore integrity failed` (ADR 0013).
- `persistence_postgres` concurrent document-write stress: atomic revise `DO` block that requires exactly one open `system_to` close, SQLSTATE mapping onto `ConcurrentWriteConflict` / `DuplicateDocumentRecord`, and live multi-session insert/revise/append-only proofs. No new migration number.
- `tepp_api` naruon HTTP interchange: versioned `https` POST contracts for analysis-run create and modular export authorization that refuse table-access URLs, review/Copilot credential headers, reserved standard-header redefinition, principal-only export idempotency keys, and lexical inference claims (ADR 0011).
- `tepp_api` naruon HTTP interchange: versioned `https` POST contracts for analysis-run create and modular export authorization that refuse table-access URLs, provider-specific API-key/secret and review/Copilot credential headers, malformed extra HTTP fields, reserved standard-header redefinition, principal-only export idempotency keys, and lexical inference claims (ADR 0011).
- `persistence_postgres` audit-event SQL contracts: append-only insert that refuses empty, oversized, or hostile `action_code` values before SQL is rendered.
- `persistence_postgres` event-instance SQL contracts: bitemporal insert and as-known-at lookup that refuse inverted valid/system windows and hostile type/lifecycle labels before SQL is rendered.
- `persistence_postgres` event-mention SQL contracts: mention identity cannot equal the instance it supports; confidence must be finite and in `(0, 1]`.
Expand Down Expand Up @@ -78,6 +94,23 @@ All notable changes to TEPP are documented here. The format follows Keep a Chang

### Changed

- The LineageWeave temporal-context read exchange no longer emits a fabricated
`idempotency-key`; that header remains reserved for retryable write/export
operations with a caller-owned operation key.
- `tepp_api` project-history requests and projections now share the strict
`temporal_core` RFC 3339 parser and nominal `KnowledgeCutoff` boundary,
rejecting unknown offsets and other timestamp forms that the transport
parser could otherwise accept.
- Coverage validation now ignores LLVM rows for multiline call and iterator
syntax that have no independently executable source coordinate, while
retaining the authored-line 100% gate.
- Removed the temporary PR-155 review-repair workflows and source-fix helper after the bounded repair; subsequent changes use the normal reviewed branch path.
- Pinned Rust branch-coverage workflows to `nightly-2026-08-21`, which is newer than the workspace Rust 1.97.1 MSRV and avoids the previous nightly/MSRV mismatch.
- Applied the documented `sqlx_live.rs` authored-coverage exclusion to the hourly release gate so live-PostgreSQL success-path coverage is not reported as a false source failure.
- Removed unreachable duplicate Naruon host-control validation because the shared `require_nonempty` boundary already rejects C0/C1 controls; retained a C1 regression case alongside the existing C0 case.
- Rust LCOV quality gating now ignores visibility-qualified function signatures
and structural match-arm labels that LLVM reports as zero-hit non-executable
lines.
- Clarified ADR 0001 so it owns Rust-first numerical/reference-backend authority while ADR 0011 owns cross-service MSA/service authority.
- Clarified ADR 0006 so it owns GPU/VRAM and model-credential boundaries; ADR 0010 now owns LLM orchestration policy and ADR 0015 owns autonomous repository-write/review/merge authority.
- Expanded ADR 0002–0005 and 0009–0011 with explicit implementation maturity, alternatives, failure/recovery, compatibility/migration, verification, and rollback/supersession boundaries where they were previously implicit.
Expand All @@ -101,7 +134,7 @@ All notable changes to TEPP are documented here. The format follows Keep a Chang

- Required 100% production line and branch coverage and complete public API docstrings.
- Required true-parameter recovery, RMSE, bias, interval coverage, temporal leakage, graph recovery, invariance, and CPU/GPU parity evidence.
- Expanded documentation contracts to require the canonical threat/privacy/assurance/API/orchestration/fitness documents, ADR policy, and every numbered ADR 0001–0016 to remain indexed and structurally complete.
- Expanded documentation contracts to require the canonical threat/privacy/assurance/API/orchestration/fitness documents, ADR policy, and every numbered ADR present in the canonical index to remain indexed and structurally complete.
- Added deterministic validation that ADR files and the index have identical decision numbers and that every ADR declares valid decision status, implementation maturity, supersession scope, core decision sections, verification, and rollback behavior.
- Added 100% statement and branch coverage for the repository quality-gate scripts.
- Made a zero executable-code coverage denominator explicit for the skeleton-only slice rather than treating it as evidence of implemented behavior.
Expand Down
35 changes: 35 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

6 changes: 6 additions & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,9 @@ members = [
"crates/validation_core",
"crates/tepp_api",
"crates/topic_measurement",
"crates/model_selection",
"crates/topic_lineage",
"crates/analysis_engine",
]
default-members = [
"crates/evidence_core",
Expand All @@ -25,6 +28,9 @@ default-members = [
"crates/validation_core",
"crates/tepp_api",
"crates/topic_measurement",
"crates/model_selection",
"crates/topic_lineage",
"crates/analysis_engine",
]

[workspace.package]
Expand Down
2 changes: 2 additions & 0 deletions DOCUMENTATION.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,8 @@ TEPP's approved PRD v0.4 and implementation plan are the primary product baselin
| Adaptive orchestration router doctoring | [`docs/research/adaptive-orchestration-router.md`](docs/research/adaptive-orchestration-router.md) |
| Topic log-ratio coordinate doctoring | [`docs/research/topic-logratio-coordinates.md`](docs/research/topic-logratio-coordinates.md) |
| Hourly NIM OpenCode doctoring | [`docs/doctoring/hourly-nim-opencode-development.md`](docs/doctoring/hourly-nim-opencode-development.md) |
| Analysis engine v1 doctoring | [`docs/doctoring/analysis-engine-v1.md`](docs/doctoring/analysis-engine-v1.md) |
| Analysis engine gap-closure doctoring | [`docs/doctoring/analysis-engine-gap-closure.md`](docs/doctoring/analysis-engine-gap-closure.md) |
| Change history | [`CHANGELOG.md`](CHANGELOG.md) |

## Maturity vocabulary
Expand Down
Loading