Skip to content

feat(relation): refuse a template copy as the source identity - #143

Merged
seonghobae merged 7 commits into
mainfrom
agent/copy-identity
Aug 24, 2026
Merged

feat(relation): refuse a template copy as the source identity#143
seonghobae merged 7 commits into
mainfrom
agent/copy-identity

Conversation

@seonghobae

Copy link
Copy Markdown
Contributor

A template or pasted copy keeps a distinct identity for relation-aware splits (ADR 0003). It cannot reuse the source document identity or become a state transition. Recovery is the computed share of recovered kinds that match known truth versus collapsing every copy to the source.

Complementary to #136 translation, #139 summarizes, and #75 method_effects (copied-text as a method source, not an identity). This crate owns copy-versus-source identity.

Local gates:

  • `cargo test -p copy_identity --all-targets` GREEN after RED (package did not exist)
  • clippy `-D warnings` PASS
  • workspace contract PASS
  • docstring contract PASS
  • lines 14/14; nightly-2026-08-01 branches 6/6

Does not allocate migration `0008`. Does not recreate `payload_semantics`, `validation_core` claim promotion (#57), or other in-flight crates.

Keep this PR draft. Preferred merge remains #46 only when exact-head required Checks pass and a qualifying independent (non-Cursor/CodeRabbit) APPROVE exists. Do not empty-commit.

A template or pasted copy keeps a distinct identity for relation-aware
splits (ADR 0003). It cannot reuse the source document identity or
become a state transition. Recovery is the computed share of copy
kinds that match known truth versus collapsing every copy to the source.
@coderabbitai

coderabbitai Bot commented Aug 17, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 2 minutes.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: cb828660-b01f-4a25-b29f-5d744f471b8b

📥 Commits

Reviewing files that changed from the base of the PR and between 4288473 and 0355d1a.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (17)
  • ARCHITECTURE.md
  • CHANGELOG.md
  • Cargo.toml
  • README.md
  • crates/copy_identity/Cargo.toml
  • crates/copy_identity/src/error.rs
  • crates/copy_identity/src/kind.rs
  • crates/copy_identity/src/lib.rs
  • crates/copy_identity/tests/copy_identity_contract.rs
  • crates/copy_identity/tests/crate_contract.rs
  • docs/TRACEABILITY.md
  • docs/adr/0003-relational-event-multiple-membership.md
  • docs/adr/README.md
  • docs/research/copy-identity.md
  • docs/research/standards-and-literature.md
  • docs/validation/temporal-event-foundation.md
  • scripts/check_workspace_contract.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae
seonghobae marked this pull request as ready for review August 20, 2026 18:02
@seonghobae

Copy link
Copy Markdown
Contributor Author

Current head 37d8697 merges protected main and fixes the previous exact-head CI root cause: repository rustfmt ordering in the copy-identity exports/tests. Focused proof passed: cargo fmt --all -- --check, cargo test -p copy_identity --offline (6 tests), workspace contracts, documentation validation, Rust docstring contract, and git diff --check. The exact-head Checks are rerunning; merge remains gated by one qualifying independent approval.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Open in Devin Review

@seonghobae

Copy link
Copy Markdown
Contributor Author

Please perform an exact-head OpenCode review of 37d8697 against base main at 7c29e7c. Review only this SHA; do not merge or update the branch.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Current-head validation update (fc9dec9): fixed the quality contract to derive the Rust crate count from scripts/check_workspace_contract.py instead of hard-coding 10. Local evidence: 89 quality tests passed; coverage 100% (991/991 statements, 442/442 branches); workspace, docstring, documentation, and diff checks passed. Please review and rerun Checks against this exact head; merge remains subject to the repository's two independent approvals and protected rules.

@seonghobae

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review

Review-only request for exact current head fc9dec90b191ff9282dc1536637aae25d061f47d. Re-review source-identity refusal for template copies, temporal/relational semantics, realistic tests, docs/APA traceability, and protected-merge requirements. Do not merge or enable auto-merge.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Queued @cwl-noema-review and @opencode-agent for PR #143 at head fc9dec90b191ff9282dc1536637aae25d061f47d. Central exact-name Actions artifacts are the durable dispatch ledger; existing review workflows remain authoritative for the final verdict and failure evidence.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Current-head review refresh for fc9dec9:

  • A template copy remains distinct from the source identity, preserving provenance and preventing copied structure from becoming an inferred source.
  • git diff --check, documentation validation, workspace contract, docstring contract, and cargo fmt --all -- --check passed locally.
  • The displayed failed checks were cancelled runs, not failed steps. The Rust Foundation CI run was explicitly requeued for this exact head and is currently queued; merge remains withheld until revalidation and qualifying approvals complete.
  • No source defect was found at this exact head; no approval is being self-issued.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Rebased current head 7d533c6 onto origin/main and retained both the copy-identity and current-main changelog entries. Local merge-tree, git diff --cached --check, and cargo fmt --all -- --check pass. Exact-head hosted checks and required independent approvals remain required before protected merge.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Current-head review request: exact head 7d533c6198492f748303869f0795fac5c8764b50 has no actionable findings in the available review data; all terminal checks are green and coverage-evidence remains queued. Please review this exact head. No merge bypass is requested.

@seonghobae
seonghobae enabled auto-merge (squash) August 24, 2026 00:56
@seonghobae

Copy link
Copy Markdown
Contributor Author

Maintainer exact-head disposition

  • Exact head: 7d533c6198492f748303869f0795fac5c8764b50
  • Exact base: c45be17a9dbce95ef81cee230e9d128abc7160ac
  • CodeGraph indexed the current checkout before review; no generated CodeGraph path is tracked.
  • Reviewed the copy/source identity boundary, temporal transition interaction, realistic recovery-rate contract, error branches, and APA/research traceability. No actionable source defect was found at this exact head.
  • Hosted Checks: all required checks pass, including Strix, Noema, OpenCode, coverage, SAST, dependency, PostgreSQL, and contract gates.
  • Review/merge state: GitHub reports REVIEW_REQUIRED; no qualifying independent human approval is present. Decision: WAIT_AND_REMEDIATE; protected normal merge remains pending approval.

# Conflicts:
#	ARCHITECTURE.md
#	CHANGELOG.md
#	Cargo.lock
#	Cargo.toml
#	README.md
#	docs/TRACEABILITY.md
#	docs/adr/0003-relational-event-multiple-membership.md
#	docs/adr/README.md
#	docs/research/standards-and-literature.md
#	docs/validation/temporal-event-foundation.md
#	scripts/check_workspace_contract.py
#	tests/quality/test_check_docstrings.py
@seonghobae
seonghobae merged commit c21c930 into main Aug 24, 2026
19 of 22 checks passed

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 2 new potential issues.

Open in Devin Review

TEPP separates stable record identity, content equality, exact text location, wire representation, authorization, and provenance. JSON wire records are explicit versioned DTOs with unknown-field rejection and reconstruct through domain validation. `SHA-256` detects content substitution but is not treated as proof of origin, authority, or chain of custody. A summary is a PROV derivation of the source document, not a state transition and not a reuse of the source identity (Moreau & Missier, 2013).

International Organization for Standardization and International Electrotechnical Commission. (2011). *Information technology—Security techniques—Privacy framework* (ISO/IEC Standard No. 29100:2011). Data minimization informs `provider_receipt`; it is not a certification claim.
TEPP separates stable record identity, content equality, exact text location, wire representation, authorization, and provenance. JSON wire records are explicit versioned DTOs with unknown-field rejection and reconstruct through domain validation. `SHA-256` detects content substitution but is not treated as proof of origin, authority, or chain of custody. A template or pasted copy is a PROV derivation of the source document, not a reuse of the source identity and not a state transition (Moreau & Missier, 2013).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Unrelated reference removed from standards doc

The change to standards-and-literature.md drops a paragraph and an ISO/IEC 29100:2011 citation from the evidence-identity section, unrelated to the copy-identity feature. The 2011 reference survives in the privacy section, so this reads as duplicate cleanup rather than a regression.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment thread CHANGELOG.md
### Added

- `copy_identity` identity gate: a template or pasted copy cannot reuse the source document identity or become a state transition; recovered copy kinds match known truth at a higher computed rate than collapsing every copy to the source (ADR 0003).
- `persistence_postgres` retention/deletion/legal-hold (migration `0007`): policy rows, legal holds that block completed deletion, evidence tombstones without raw-source restore, analysis exclusion only for `logical_revocation`/`identity_tombstone` (not `cache_export_removal`), and deletion requests bound to the cited retention policy's tenant/class/purpose.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Unrelated CHANGELOG entry for persistence_postgres migration 0007

The CHANGELOG diff adds two entries: the copy_identity gate (expected) and a persistence_postgres retention/deletion/legal-hold (migration 0007) entry at CHANGELOG.md. The latter is unrelated to this PR's stated scope (copy-versus-source identity) and the author description explicitly disclaims allocating migrations. retention_sql.rs does exist in the tree, so this may be a pre-existing/merge-carried entry rather than newly introduced work, but its appearance in this PR's diff is worth confirming to avoid over-claiming capabilities not delivered by this change.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant