Skip to content

Bind restart analyst facts to validated detection source and event input - #73

Open
raylee-hawkins wants to merge 17 commits into
feature/hoxline-case-growth-convergence-v1from
agent/server-return-foundation
Open

raylee-hawkins wants to merge 17 commits into
feature/hoxline-case-growth-convergence-v1from
agent/server-return-foundation

Conversation

@raylee-hawkins

@raylee-hawkins raylee-hawkins commented Sep 6, 2026 •

Copy link
Copy Markdown
Contributor

Objective and system role

Complete Validation's part of the existing server-return foundation: provide source-executed HO-DET-001 event facts for bounded analyst support. Detection source and the original corpus remain unchanged.

New capability and files

scripts/detection_quality.py adds controlled fixture and operator-input fact producers plus whole-result replay verification. It uses the existing canonical predicate evaluator, exports only sanitized categories/hashes, and binds exact source, corpus, mapping, validator, event and execution identities. tests/test_detection_quality.py exercises the new contract. The parity pin and standalone sweep fixes are now owned by updated base #71. This PR's current review surface is only these two facts/quality files. Updated base #71 also closes report-heading promotion, conflicting identities, unbound JSON/YAML claims/statuses and split nested authority paths. Its shared promotion vocabulary retains parent authority through containers, and its rejected-fixture input exception requires a unique registered controlled owner, matching report case and exact direct boolean subtree with consistent expectations.

Final facts recovery commits c11e65b,0a26ac3,e35ad27 and9ee60c1 plus base reconciliation f7baf55 fail closed on unsupported process selector values, retaining canonical matcher semantics and allowed case/subset behavior. Oversized integer event and separate --verify receipt input return sanitized BLOCKED without raw event/path/traceback. The final41 quality/facts tests (25 added fact-contract tests) and independent cross-review pass. All six technical review conversations have evidence-backed resolutions; AI engineering replies are not eligible HUMAN approval.

Non-finite receipt canonicalization now raises the existing sanitized QualityError in both CLI and owner verification APIs. Actual positive/negative overflow JSON and inf/-inf/NaN tests reject without private context or traceback; finite canonical bytes/hashes are unchanged. Base #71 now supplies an explicitly labeled standalone registry mode while keeping required-source verification the default.

Receipt intake now reads binary data with a 1 MiB limit before decoding or strict JSON parsing; real quality receipts exceeding 64 KiB remain supported. Explicit empty --facts-case/--facts-event/--execution-id values select the facts validation path and reject before source lookup or fallback quality generation. Nine empty-option combinations, bounded-read ordering, oversized receipt CLI sanitization and a genuine large-receipt replay are covered. Local facts recovery commit9ee60c126629c445f9d599e8fb1f4d686cd10adb passed41 focused tests.

Dependencies and human review order

Stacked on validation #71 (feature/hoxline-case-growth-convergence-v1). Selected detection source: 56cad4f726c0d3988c9464693ce7c127c8f63cad; its required convergence review is detections #47. Platform #89 consumes this fact contract. Review validation before the dependent platform handoff, then the org/Website source-selection consumers. Required code is not yet on main.

Measured validation and hostile results

Current head: f7baf556f86e393bb3da96fa34518c7ccee0f5b1, with base b207c1fc48dcb247ef3d53812db73bd00fdaee11. Eleven ordinary branch merges preserved both histories; no PR was merged.

  • Full validation suite: 236 tests passed.
  • Targeted quality/facts suite: 41 tests passed, including 25 added fact-contract tests.
  • Original HO-DET-001 corpus: 14 events, 7 observed matches and 7 nonmatches; original expected results preserved.
  • All 39 validation-package checks passed.
  • Rehashed fact/input/result tampering, wrong execution/fixture/source, changed validator, unknown event fields, duplicate/non-finite/oversized input and exact controlled-fixture relabeling fail closed.
  • EventID is classified but is not enforced by this rule. Argument indicators are lexical source matches, not decoded payload behavior. Parent context stays unknown.

Commands:

python -B -m unittest discover -s tests
python -B -m unittest discover -s tests -p test_detection_quality.py
python -B scripts/verify_all_validation_packages.py --source-contract required
python -B scripts/detection_quality.py --detections-root DETECTIONS_ROOT --detections-ref 56cad4f726c0d3988c9464693ce7c127c8f63cad --facts-case pos-001-powershell-enc --execution-id HO-DET-001-20260907T120000Z-FACT01

The final command is a path template; resolve the operator-selected detection checkout. Commands emit stdout only.

Exact-head CI

All eight applicable workflows at f7baf55 succeeded:

Cross Repo Claim Parity was manually dispatched at the exact successor head because its existing PR trigger targets main, while this PR targets the repaired convergence base. ID/HO-DET-012 path checks were not triggered on this facts-only successor; no check was disabled. Baseline includes hosted Windows/Ubuntu contracts. These are controlled hosted executions, not endpoint or backend evidence. Current review diff remains exactly scripts/detection_quality.py and tests/test_detection_quality.py.

AI authority and proof boundary

Validation supplies facts; AI does not define outcomes. Operator-input evaluation has no invented expectation (expected_match=null) and remains operator-attested, origin unauthenticated, SOURCE_EXISTS. Controlled fixture results retain their controlled ceiling. No inference, private runtime, ledger append, disposition, closure, schedule activation or proof/public-safe promotion is performed.

Private-data and claim scans

Outgoing source/tests and this body were inspected. Security vocabulary and controlled invalid input strings are intentional regression material. No unexplained private data, credential, private route or unsupported runtime/public claim was found. No original evidence timestamps or proof counts changed.

Rollback and merge gate

Revert the scoped commits after any separately approved landing; before landing, retain the previous selected source set. Do not activate runtime from this fact contract.

Green CI is not approval. AI review is not human approval. No merge is authorized. Visible eligible human GitHub review and the separate human-supplied MERGE_APPROVED remain required.

@raylee-hawkins raylee-hawkins changed the title Fix restart parity selection of repaired detection source Bind restart analyst facts to validated detection source and event input Sep 8, 2026
@raylee-hawkins
raylee-hawkins marked this pull request as ready for review October 3, 2026 01:18
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T05:27:01.768926Z f7baf55 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e796f96c21

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/detection_quality.py

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8ff94cef54

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/detection_quality.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f655f6f74d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/detection_quality.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 05323b1afa

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/detection_quality.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 636c82041a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/detection_quality.py Outdated
Comment thread scripts/detection_quality.py Outdated
@raylee-hawkins
raylee-hawkins added this pull request to stack #74 October 3, 2026 12:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant