Skip to content

feat: admit enterprise-document evidence into query and packet - #52

Merged
1wgrumph merged 6 commits into
mainfrom
feat/46-document-evidence
Sep 30, 2026
Merged

1wgrumph merged 6 commits into
mainfrom
feat/46-document-evidence

Conversation

@1wgrumph

Copy link
Copy Markdown
Contributor

Summary

Admits enterprise-document evidence into bran query and bran packet (#46). This connects the four adapters (DOCX, XLSX, PPTX, PDF) to the normal query surface.

  • Discovery: documents are found by extension, capped at 64 files. Each adapter projection is wrapped in the RFC: BRAN evidence envelope for managed enterprise-document parsers #20 evidence envelope and schema-validated before admission. An envelope that cannot be represented is refused as oversized.
  • Output: query and packet return admitted anchors in an additive document_evidence member, capped at 32 matches, with source type, native locator, source digest, fidelity and derivation. Document matches count toward query coverage and outcome. Packet excerpts obey the byte and token budgets and are included in the accounting.
  • Safety:
    • OCR-derived anchors are labelled and never ranked as byte-derived text.
    • Refused or DLP-failing documents never enter a packet. They get a typed refusal that does not echo the unsafe path.
    • Locators themselves pass the DLP and public-boundary checks.
    • Document paths are excluded from Markdown ranking.
  • Inspection: bran document inspect prints an envelope and writes nothing.
  • Unchanged output: repositories without documents produce byte-identical output. bran-cli now depends on the in-workspace bran-document crate; bran-core still has no dependencies.

Closes #46

Verification

  • ./tools/ci/check.sh --fast and --full pass on the branch, which is current with main. No new external dependencies.
  • document_admission CLI tests: 15 pass, covering all four formats, inspection, refusals, DLP, budgets, coverage, determinism and unchanged document-free output.
  • Independent review (Codex GPT-6 Astra) confirmed byte-identical document-free output on five repositories and the 64-file and 32-match caps. It returned REPAIR_REQUIRED with five findings, all fixed in f846fc1 with tests that failed first:
    • file names bypassed DLP;
    • refusals echoed unsafe paths;
    • document excerpts skipped the packet budget;
    • oversized envelopes were admitted despite failing the schema;
    • document matches reported the query as a miss.

Not covered: no real OCR producer exists here, so the OCR labelling is pinned by unit tests.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GXsmZAgLAftTb8E5oswz82

Muse Code and others added 6 commits September 30, 2026 08:03
Route import through the conformance registry by format and wrap the
projection in a #20 envelope: anchors, fidelity, digests, and
truncation/unavailable receipts. DLP and public-boundary findings keep
their typed refusals; anything that cannot become a valid envelope is
refused, never invented. DOCX/PPTX plug in as a projection reader arm.

Refs #46
CLI tests for document inspect, query/packet XLSX and PDF anchors,
typed malformed/DLP refusals, unsupported-format routing, and
byte-identical output without document evidence. Registered in the
test budget.

Refs #46
New read-only document inspect command plus an appended
document_evidence member on query and packet: admitted sources with
digests and fidelity, ranked anchor matches with native locators and
derivation, typed refusals, and unsupported formats. Document paths
no longer rank as Markdown sources; roots without document files
return byte-identical output.

Closes #46
Validate emitted locators and envelope receipts, omit unsafe refusal paths, budget document excerpts, and include document matches in query coverage. Preserve exact reviewer packages for five red-to-green CLI regressions.

Refs #46
@1wgrumph
1wgrumph merged commit bcf6ee9 into main Sep 30, 2026
5 checks passed
@1wgrumph
1wgrumph deleted the feat/46-document-evidence branch September 30, 2026 14:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Admit enterprise-document evidence into bran query and bran packet

1 participant