Repository navigation
Bind restart analyst facts to validated detection source and event input - #73
raylee-hawkins wants to merge 17 commits into
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e796f96c21
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8ff94cef54
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f655f6f74d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 05323b1afa
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 636c82041a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Objective and system role
Complete Validation's part of the existing server-return foundation: provide source-executed HO-DET-001 event facts for bounded analyst support. Detection source and the original corpus remain unchanged.
New capability and files
scripts/detection_quality.pyadds controlled fixture and operator-input fact producers plus whole-result replay verification. It uses the existing canonical predicate evaluator, exports only sanitized categories/hashes, and binds exact source, corpus, mapping, validator, event and execution identities.tests/test_detection_quality.pyexercises the new contract. The parity pin and standalone sweep fixes are now owned by updated base #71. This PR's current review surface is only these two facts/quality files. Updated base #71 also closes report-heading promotion, conflicting identities, unbound JSON/YAML claims/statuses and split nested authority paths. Its shared promotion vocabulary retains parent authority through containers, and its rejected-fixture input exception requires a unique registered controlled owner, matching report case and exact direct boolean subtree with consistent expectations.Final facts recovery commits c11e65b,0a26ac3,e35ad27 and9ee60c1 plus base reconciliation f7baf55 fail closed on unsupported process selector values, retaining canonical matcher semantics and allowed case/subset behavior. Oversized integer event and separate --verify receipt input return sanitized BLOCKED without raw event/path/traceback. The final41 quality/facts tests (25 added fact-contract tests) and independent cross-review pass. All six technical review conversations have evidence-backed resolutions; AI engineering replies are not eligible HUMAN approval.
Non-finite receipt canonicalization now raises the existing sanitized QualityError in both CLI and owner verification APIs. Actual positive/negative overflow JSON and inf/-inf/NaN tests reject without private context or traceback; finite canonical bytes/hashes are unchanged. Base #71 now supplies an explicitly labeled standalone registry mode while keeping required-source verification the default.
Receipt intake now reads binary data with a 1 MiB limit before decoding or strict JSON parsing; real quality receipts exceeding 64 KiB remain supported. Explicit empty --facts-case/--facts-event/--execution-id values select the facts validation path and reject before source lookup or fallback quality generation. Nine empty-option combinations, bounded-read ordering, oversized receipt CLI sanitization and a genuine large-receipt replay are covered. Local facts recovery commit9ee60c126629c445f9d599e8fb1f4d686cd10adb passed41 focused tests.
Dependencies and human review order
Stacked on validation #71 (
feature/hoxline-case-growth-convergence-v1). Selected detection source:56cad4f726c0d3988c9464693ce7c127c8f63cad; its required convergence review is detections #47. Platform #89 consumes this fact contract. Review validation before the dependent platform handoff, then the org/Website source-selection consumers. Required code is not yet on main.Measured validation and hostile results
Current head:
f7baf556f86e393bb3da96fa34518c7ccee0f5b1, with baseb207c1fc48dcb247ef3d53812db73bd00fdaee11. Eleven ordinary branch merges preserved both histories; no PR was merged.Commands:
The final command is a path template; resolve the operator-selected detection checkout. Commands emit stdout only.
Exact-head CI
All eight applicable workflows at f7baf55 succeeded:
Cross Repo Claim Parity was manually dispatched at the exact successor head because its existing PR trigger targets main, while this PR targets the repaired convergence base. ID/HO-DET-012 path checks were not triggered on this facts-only successor; no check was disabled. Baseline includes hosted Windows/Ubuntu contracts. These are controlled hosted executions, not endpoint or backend evidence. Current review diff remains exactly scripts/detection_quality.py and tests/test_detection_quality.py.
AI authority and proof boundary
Validation supplies facts; AI does not define outcomes. Operator-input evaluation has no invented expectation (
expected_match=null) and remains operator-attested, origin unauthenticated,SOURCE_EXISTS. Controlled fixture results retain their controlled ceiling. No inference, private runtime, ledger append, disposition, closure, schedule activation or proof/public-safe promotion is performed.Private-data and claim scans
Outgoing source/tests and this body were inspected. Security vocabulary and controlled invalid input strings are intentional regression material. No unexplained private data, credential, private route or unsupported runtime/public claim was found. No original evidence timestamps or proof counts changed.
Rollback and merge gate
Revert the scoped commits after any separately approved landing; before landing, retain the previous selected source set. Do not activate runtime from this fact contract.
Green CI is not approval. AI review is not human approval. No merge is authorized. Visible eligible human GitHub review and the separate human-supplied
MERGE_APPROVEDremain required.