// Offline evidence classifier. No CloudWatch evaluation, AWS access or authorization. export function assessPacket(p) { const hold = (reason) => ({ decision: 'HOLD', reason, authorizesAwsChange: false }); if (!p || p.scope !== 'PROVISIONED_REALTIME_SINGLE_VARIANT_BLUE_GREEN_CANARY') return hold('scope'); if (p.marketplace !== false || p.inf1 !== false) return hold('excluded-or-unknown-feature'); if (!p.endpoint || !p.oldConfig || !p.newConfig || p.oldConfig === p.newConfig || p.variant !== 'AllTraffic' || p.oldVariant !== p.variant || p.newVariant !== p.variant) return hold('update-identity'); if (!p.packetRevision || !p.owner || !p.evidenceReference) return hold('packet-provenance'); if (p.alarmReadPermission !== 'evidenced' || !p.permissionReference) return hold('alarm-permission'); if (p.previousPackageCompatibility !== 'evidenced' || !p.recoveryReference) return hold('recovery-evidence'); if (p.capacityReview !== 'evidenced' || !p.capacityReference) return hold('capacity-evidence'); const a = p.observer; if (!a || a.namespace !== 'AWS/SageMaker' || a.metric !== 'ModelLatency' || a.unit !== 'Microseconds' || a.statistic !== 'local-sum-divided-by-count') return hold('metric-contract'); if (a.endpoint !== p.endpoint || a.config !== p.newConfig || a.variant !== p.variant) return hold('metric-population'); if (!['missing', 'breaching', 'notBreaching', 'ignore'].includes(a.treatMissingData) || !a.alarmReference) return hold('alarm-contract'); if (!Number.isSafeInteger(a.minimumSamples) || a.minimumSamples < 1 || !Number.isFinite(a.stopAboveMicros) || a.stopAboveMicros <= 0) return hold('owner-criterion'); if (!Array.isArray(p.expectedWindows) || p.expectedWindows.length !== 2 || [p.expectedWindows[0], p.expectedWindows[1]].some((w) => !w || typeof w !== 'object' || !Number.isSafeInteger(w.start) || !Number.isSafeInteger(w.end) || w.end - w.start !== 60) || p.expectedWindows[0].end !== p.expectedWindows[1].start) return hold('window-contract'); if (!Array.isArray(p.observations) || p.observations.length !== 2) return hold('missing-observations'); const means = []; for (let i = 0; i < 2; i++) { const o = p.observations[i]; const w = p.expectedWindows[i]; if (!o || o.start !== w.start || o.end !== w.end || o.endpoint !== p.endpoint || o.config !== p.newConfig || o.variant !== p.variant || o.unit !== 'Microseconds') return hold('observation-identity'); if (!Number.isSafeInteger(o.sampleCount) || o.sampleCount < a.minimumSamples || !Number.isSafeInteger(o.sumLatencyMicros) || o.sumLatencyMicros < 0) return hold('observation-coverage'); means.push(o.sumLatencyMicros / o.sampleCount); } // This deliberately chosen worksheet policy is not CloudWatch M-of-N logic. if (means.every((m) => m > a.stopAboveMicros)) return { decision: 'STOP_REVIEW', reason: 'both-local-windows-breach', meansMicros: means, authorizesAwsChange: false }; if (means.some((m) => m > a.stopAboveMicros)) return { decision: 'HOLD', reason: 'mixed-local-windows', meansMicros: means, authorizesAwsChange: false }; if (p.qualityEvidence !== 'mature-owner-reviewed') return { decision: 'HOLD_QUALITY', reason: 'serving-bounded-quality-unresolved', meansMicros: means, authorizesAwsChange: false }; return { decision: 'REVIEW_READY', reason: 'bounded-packet-only', meansMicros: means, authorizesAwsChange: false }; } export function weightedMean(groups) { if (!Array.isArray(groups) || !groups.length || groups.some((g) => !Number.isSafeInteger(g.count) || g.count < 1 || !Number.isSafeInteger(g.sum) || g.sum < 0)) throw new Error('Invalid counted populations'); const count = groups.reduce((n, g) => n + g.count, 0); const sum = groups.reduce((n, g) => n + g.sum, 0); if (!Number.isSafeInteger(count) || !Number.isSafeInteger(sum)) throw new Error('Unsafe total'); return sum / count; }