Research portal

Mathematical note

Query-registered semantic preservation

math/query-registered-preservation.md

Edition
Site v0.3.0 · continuous main snapshot
Source revision
ec2865b0eac15148675c629981a545632b3571c5
Extent
858 words
Public route
https://www.cordana.dev/math/query-registered-preservation/
Mapped records1 mapped record

Direct repository links only; no document-level evidence status is implied.

This note refines Candidate 017 with the interpreter, representation-dependency, vocabulary, authenticity, and access boundaries established by library and archival science. The contract does not promise to preserve all future meaning. It makes a finite claim that can fail.

Preservation package

For version vv, define

Pv=(Bv,Mv,Fv,Sv,Vv,Dv,Av,Xv),P_v=(B_v,M_v,F_v,S_v,V_v,D_v,A_v,X_v),

where:

  • BvB_v is payload bytes;
  • MvM_v is metadata, evidence, provenance, and fixity records in bytes;
  • FvF_v is format and rendering dependencies;
  • SvS_v is schema and type constraints;
  • VvV_v is vocabulary, authority, identity, and mapping versions;
  • DvD_v is the designated interpreter community and its assumed capabilities;
  • AvA_v is authenticity/custody evidence and authorized access state; and
  • XvX_v is executable dependencies, tests, emulators, or migration tooling.

The tuple is typed. Fixity of BvB_v does not establish truth, authenticity, interpretability, or authorized accessibility. Provenance in MvM_v records lineage; it does not validate assertions.

Registered query contract

For query family qQq\in\mathcal Q, declare native output space Yq\mathcal Y_q, distance dqd_q, tolerance ϵq\epsilon_q, evidence obligations LqL_q, supported community DqD_q, and decision horizon TqT_q. For source package P0P_0 and a candidate transformed package PvP_v, require

PrqDQ[dq(q(P0),q(Pv))>ϵq]δq,\Pr_{q\sim\mathcal D_Q} \left[d_q(q(P_0),q(P_v))>\epsilon_q\right]\le\delta_q,

where dqd_q and ϵq\epsilon_q share the query's native unit and δq\delta_q is a dimensionless failure probability. The evaluation distribution DQ\mathcal D_Q has frozen development, held-out in-family, and adversarial migration splits.

Evidence reachability is

RL(Pv)=qQLqL^q(Pv)qQLq,R_L(P_v)= \frac{\sum_{q\in\mathcal Q}|L_q\cap\widehat L_q(P_v)|} {\sum_{q\in\mathcal Q}|L_q|},

where LqL_q is the registered evidence set and L^q(Pv)\widehat L_q(P_v) is the set recoverable with valid lineage from PvP_v. RLR_L is dimensionless. It does not score whether the evidence supports a claim; that requires a separate inference and decision contract.

Interpreter and dependency validity

Let c(D,t)c(D,t) be a versioned capability vector for the interpreter community at time tt: supported languages, schemas, units, software, cryptographic algorithms, domain conventions, and required practiced procedures. Let r(Pv)r(P_v) be the corresponding requirements. Interpretability is

I(Pv,D,t)=1[c(D,t)r(Pv)],I(P_v,D,t)=\mathbf 1[c(D,t)\succeq r(P_v)],

a dimensionless predicate under a declared partial order. “Human readable” or “standard format” is insufficient unless the supported community and dependencies are named.

For dependency graph Gv=(Nv,Ev)G_v=(N_v,E_v) and root package nodes RvR_v, required closure is

cl(Rv)={nNv:rRv with a required path rn}.\operatorname{cl}(R_v)= \{n\in N_v:\exists r\in R_v\text{ with a required path }r\leadsto n\}.

Missing-dependency rate is

mv={ncl(Rv):n unavailable or invalid}cl(Rv),m_v= \frac{|\{n\in\operatorname{cl}(R_v):n\text{ unavailable or invalid}\}|} {|\operatorname{cl}(R_v)|},

which is dimensionless. Criticality weights may be reported separately, but a weighted mean cannot hide the loss of a dependency required by every query.

Migration and vocabulary drift

For migration Tv:Pv1PvT_v:P_{v-1}\rightarrow P_v, maintain a manifest containing source/target versions, transformed and retained fields, known loss, dependencies, tests, reviewer/authority, and rollback or source-recovery path. Query regression is

Δq(v)=dq(q(Pv1),q(Pv)),\Delta_q^{(v)}= d_q(q(P_{v-1}),q(P_v)),

in the native query unit. Vocabulary or authority mappings are separate versioned relations

RvEv1×Ev×{same,broader,narrower,split,merge,contested}.R_v\subseteq E_{v-1}\times E_v\times \{\mathrm{same},\mathrm{broader},\mathrm{narrower}, \mathrm{split},\mathrm{merge},\mathrm{contested}\}.

A merge cannot silently transfer all evidence from both prior entities. Query tests must include namesakes, renames, splits, merges, multilingual labels, contested mappings, and temporal concept change.

Availability decomposition

For query qq, time tt, and community DD, a useful decomposition is

U(q,t,D)=pbitsprenderpsemanticpauthenticpauthorizedV(q,D)C(q,t,D).U(q,t,D)= p_{\mathrm{bits}}p_{\mathrm{render}}p_{\mathrm{semantic}} p_{\mathrm{authentic}}p_{\mathrm{authorized}}V(q,D)-C(q,t,D).

The five pp terms are dimensionless conditional probabilities; VV and CC share one declared decision unit. The product is a checklist unless dependence among failures is explicitly modelled. Report each component and joint failure cases; do not claim independence by notation.

Registered and unregistered use

The registered contract permits direct success/failure decisions. New unregistered query qq' receives one of three typed outcomes:

  1. answer with a proof that its required fields and evidence are covered by an existing contract;
  2. recover retained source/dependencies and evaluate a new contract; or
  3. abstain as unsupported.

Unregistered-query regret over set Q\mathcal Q' is

Rnew=1QqQ[L(q,Pv)L(q,Pfull)],R_{\mathrm{new}}= \frac{1}{|\mathcal Q'|} \sum_{q'\in\mathcal Q'} \left[ L(q',P_v)-L(q',P_{\mathrm{full}}) \right],

where LL uses the query's declared decision loss. Report results by query family because averaging can hide systematic loss for a user, language, period, or evidence class.

Lifecycle accounting

For policy π\pi spanning capture through disposition, keep the native outcome vector

C(π)=(Byear,Elife,Hcurator,Tquery,Trecover,Lwrong,Lunreadable,Lprivacy),\mathbf C(\pi)= (B_{\mathrm{year}},E_{\mathrm{life}},H_{\mathrm{curator}}, T_{\mathrm{query}},T_{\mathrm{recover}}, L_{\mathrm{wrong}},L_{\mathrm{unreadable}},L_{\mathrm{privacy}}),

where byte-years, joules, person-hours, seconds, and task-native loss units are not added without published conversion weights. Charge payload, metadata, indexes, replicas, dependencies, emulators, tests, migrations, reviewer work, restore drills, legal holds, and verified deletion.

Byte reduction is

ρB=1Bv+Mv+Xv+RvB0+M0+X0+R0,\rho_B=1- \frac{|B_v|+|M_v|+|X_v|+|R_v|} {|B_0|+|M_0|+|X_0|+|R_0|},

where every magnitude is bytes and ρB\rho_B is dimensionless. Backups or retained raw sources cannot be excluded from the numerator while supplying recovery.

Strongest null and rejection

Compare learned compaction with full version history, indexed snapshots plus suffix log, materialized views, key compaction and tombstones, lossless compression/deduplication, tiered cold archive, and an OAIS/PREMIS-style package with versioned schema/vocabulary and query-regression tests.

Reject the refinement when:

  1. ordinary packaging plus query regression matches registered-query error, evidence reachability, recovery, and lifecycle cost;
  2. supported queries or interpreter capabilities are chosen after migration;
  3. fixity, provenance, citation, ontology consistency, or findability is substituted for correctness;
  4. unregistered queries receive invented answers instead of recovery or abstention;
  5. required deletion, holds, privacy, or authorization are omitted;
  6. metadata, dependencies, migration, reviewer work, and cold fallback are not charged; or
  7. records survive turnover but operators cannot safely interpret or use them.

Editable diagram: query-registered-preservation.mmd.