Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
71 commits
Select commit Hold shift + click to select a range
07514a9
feat: converge case growth and expand fixture review
raylee-hawkins Jul 22, 2026
cff5924
fix: normalize volatile state and bounded metrics
raylee-hawkins Jul 22, 2026
46cd438
fix: compare generated surface repository revisions
raylee-hawkins Jul 22, 2026
680d713
chore: record converged seven-repository snapshot
raylee-hawkins Jul 22, 2026
769622b
fix: classify generated-surface revision cycles
raylee-hawkins Jul 22, 2026
6721b49
chore: refresh converged snapshot after cycle hardening
raylee-hawkins Jul 22, 2026
e0c18ee
fix: verify generated and checked self revisions
raylee-hawkins Jul 23, 2026
9ca329d
fix: resolve review roots from supplied indexes
raylee-hawkins Jul 23, 2026
2f22d64
chore: refresh snapshot after clean-room hardening
raylee-hawkins Jul 23, 2026
4c96f52
fix: sanitize blocked diagnostics in installed runs
raylee-hawkins Jul 23, 2026
ab42606
chore: refresh final clean-room snapshot
raylee-hawkins Jul 23, 2026
f2ebea1
chore: refresh post-CI convergence snapshot
raylee-hawkins Jul 23, 2026
ac73746
fix(hoxline): bind replay and content authority
Jul 23, 2026
8652d86
ci(hoxline): pin final platform repair head
Jul 23, 2026
500c47b
chore(hoxline): refresh atomic case growth pair
Jul 23, 2026
8ddb8ee
chore(hoxline): converge atomic reviewer snapshot
Jul 23, 2026
5cf99d3
ci(hoxline): pin final seven-source review heads
Jul 23, 2026
72de2b3
fix(hoxline): bind currentness to reviewed source trees
Jul 23, 2026
4b890fc
chore(hoxline): refresh current convergence pair
Jul 23, 2026
3f2cf1b
fix(hoxline): bind detached command-center observation
Jul 23, 2026
352cc0b
chore(hoxline): refresh final content-linked pair
Jul 23, 2026
752fade
chore(hoxline): bind refreshed platform authority
Jul 23, 2026
fd3a0b1
ci(hoxline): verify sealed seven-source content
Jul 23, 2026
105e904
test(hoxline): isolate command-center observation environment
Jul 23, 2026
8a5e6bc
fix(hoxline): consume dual source identities
Jul 23, 2026
f6edb75
chore(hoxline): refresh content-addressed case-growth pair
Jul 23, 2026
6736f52
fix(hoxline): require command-center content identity
Jul 23, 2026
2be9e12
chore(hoxline): refresh explicit content identities
Jul 23, 2026
887f0bb
fix(case-growth): anchor snapshots to authority content
Jul 23, 2026
cc0e3e1
fix(case-growth): separate content and head observations
Jul 23, 2026
e6e6e8c
ci(hoxline): consume stable content manifest
Jul 23, 2026
47c72da
chore(case-growth): refresh atomic convergence pair
Jul 23, 2026
d2ce9d9
fix(case-growth): verify reviewed rewrite projections
Jul 23, 2026
1387938
fix(hoxline): bind review authority and replay integrity
Jul 23, 2026
6d15813
fix(hoxline): harden recursive review authority
Jul 23, 2026
d8aeb25
ci(hoxline): pin hardened authority sources
Jul 23, 2026
f725dae
ci(hoxline): consume final reviewed code matrix
Jul 23, 2026
088e559
ci(hoxline): pin final website review matrix
Jul 23, 2026
ee17f78
ci(hoxline): pin final generator review matrix
Jul 23, 2026
fb0cb3b
chore(case-growth): refresh hardened atomic snapshot
Jul 23, 2026
768fd22
chore(hoxline): refresh converged Case Growth pair
Jul 23, 2026
0b40f45
chore(hoxline): seal final converged Case Growth pair
Jul 23, 2026
84c7be5
chore(hoxline): record merge-rehearsal observation
Jul 23, 2026
92e40bf
chore(hoxline): seal final strategy-resilient Case Growth pair
Jul 23, 2026
385f3a0
chore(hoxline): seal explicit-observation Case Growth pair
Jul 23, 2026
804b19e
chore(case-growth): refresh rewrite-resilient authority pair
Jul 23, 2026
6acb751
fix(case-growth): model historical and blocked index states
Jul 23, 2026
7c842a1
chore(case-growth): refresh schema-aware index pair
Jul 23, 2026
ad8c450
chore(case-growth): refresh final source observations
Jul 23, 2026
29772b1
chore(case-growth): refresh CI repair observations
Jul 23, 2026
228135b
ci(hoxline): verify the exact seven-head source set
Jul 23, 2026
fc1f658
chore(case-growth): refresh exact CI source observations
Jul 23, 2026
5204ef3
chore(case-growth): refresh exact website observations
Jul 23, 2026
b0899fe
fix(hoxline): make review paths checkout-root invariant
Jul 23, 2026
b0945c4
fix(case-growth): bind detached refs to exact heads
Jul 23, 2026
58a8915
chore(case-growth): refresh detached-source pair
Jul 23, 2026
193f929
ci(hoxline): verify reviewed seven-source heads
Jul 24, 2026
6616877
chore(case-growth): refresh reviewed head observations
Jul 24, 2026
9a8ff9b
chore(case-growth): finalize settled source observations
Jul 24, 2026
cad8114
chore(case-growth): finalize merge-resilient observations
Jul 24, 2026
dbfd4a1
fix(case-growth): bind authority to stored repository origin
Jul 24, 2026
17f03c4
chore(case-growth): refresh atomic convergence pair
Jul 24, 2026
1cb97ef
fix(hoxline): isolate Git authority from ambient state
Jul 24, 2026
b2e0b46
ci(hoxline): select hardened seven-source revisions
Jul 24, 2026
55cf0f5
chore(case-growth): seal hardened source pair
Jul 24, 2026
63ad111
ci(hoxline): select pair-containing convergence sources
Jul 24, 2026
0dcade7
ci(hoxline): exercise rewritten-observation hardening
Jul 24, 2026
dd13842
chore(hoxline): regenerate repaired case-growth pair
Jul 24, 2026
52867ee
ci(hoxline): resolve reviewed siblings from one manifest
Jul 24, 2026
6f56e7c
chore(hoxline): refresh converged case growth pair
Jul 24, 2026
cd797da
ci(hoxline): consume reviewed stabilization manifest
Jul 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
302 changes: 270 additions & 32 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,63 +4,301 @@ on:
pull_request:
push:

permissions:
contents: read

jobs:
test:
hoxline-trust-boundaries:
runs-on: ubuntu-latest
env:
HAWKINS_COMMAND_CENTER_IMMUTABLE_OBSERVED_SHA: 5c6127f5acc1031bae2528df3ce1f197da882100
HAWKINS_HOXLINE_EVENT_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
strategy:
fail-fast: false
matrix:
python-version: ["3.11", "3.12"]

steps:
- uses: actions/checkout@v4
- name: Check out Hoxline PR revision
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
path: org/hoxline
ref: ${{ github.event.pull_request.head.sha || github.sha }}
fetch-depth: 0
persist-credentials: false

- name: Check out command center
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
repository: HawkinsOperations/.github
ref: 5c6127f5acc1031bae2528df3ce1f197da882100
path: org/.github
fetch-depth: 0
persist-credentials: false

- name: Resolve reviewed sibling revisions
id: reviewed
shell: bash
run: |
python - <<'PY'
from pathlib import Path
import json
import os

manifest_path = Path("org/.github/governance/CONVERGENCE_SOURCE_MANIFEST.json")
manifest = json.loads(manifest_path.read_text(encoding="utf-8"))
entries = {
item["repository"]: item
for item in manifest.get("repositories", [])
if isinstance(item, dict) and isinstance(item.get("repository"), str)
}
required = {
"hawkinsoperations-detections": "detections",
"hawkinsoperations-validation": "validation",
"hawkinsoperations-platform": "platform",
"hawkinsoperations-proof": "proof",
"hawkinsoperations-website": "website",
}
if set(entries) != {
".github",
*required,
"hoxline",
}:
raise SystemExit(f"reviewed manifest must contain exactly seven repositories; got {sorted(entries)}")
with Path(os.environ["GITHUB_OUTPUT"]).open("a", encoding="utf-8") as output:
for repository, output_name in required.items():
revision = entries[repository].get("revision")
if not isinstance(revision, str) or len(revision) != 40:
raise SystemExit(f"{repository} lacks an immutable reviewed revision")
int(revision, 16)
output.write(f"{output_name}={revision}\n")
PY

- name: Check out detection authority
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
repository: HawkinsOperations/hawkinsoperations-detections
ref: ${{ steps.reviewed.outputs.detections }}
path: org/hawkinsoperations-detections
fetch-depth: 0
persist-credentials: false

- name: Check out validation authority
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
repository: HawkinsOperations/hawkinsoperations-validation
ref: ${{ steps.reviewed.outputs.validation }}
path: org/hawkinsoperations-validation
fetch-depth: 0
persist-credentials: false

- name: Check out platform authority
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
repository: HawkinsOperations/hawkinsoperations-platform
ref: ${{ steps.reviewed.outputs.platform }}
path: org/hawkinsoperations-platform
fetch-depth: 0
persist-credentials: false

- name: Check out proof authority
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
repository: HawkinsOperations/hawkinsoperations-proof
ref: ${{ steps.reviewed.outputs.proof }}
path: org/hawkinsoperations-proof
fetch-depth: 0
persist-credentials: false

- name: Check out website rendering contract
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
repository: HawkinsOperations/hawkinsoperations-website
ref: ${{ steps.reviewed.outputs.website }}
path: org/hawkinsoperations-website
fetch-depth: 0
persist-credentials: false

- name: Verify and record exact seven-repository checkout
working-directory: org/hoxline
shell: bash
run: |
python - <<'PY'
from pathlib import Path
import json
import os
import subprocess

- uses: actions/setup-python@v5
root = Path("..").resolve()
manifest = json.loads(
(root / ".github" / "governance" / "CONVERGENCE_SOURCE_MANIFEST.json").read_text(
encoding="utf-8"
)
)
reviewed = {
item["repository"]: item.get("revision")
for item in manifest["repositories"]
if item["repository"] not in {".github", "hoxline"}
}
expected = [
".github",
"hawkinsoperations-detections",
"hawkinsoperations-validation",
"hawkinsoperations-platform",
"hawkinsoperations-proof",
"hawkinsoperations-website",
"hoxline",
]
immutable = {
".github": os.environ["HAWKINS_COMMAND_CENTER_IMMUTABLE_OBSERVED_SHA"],
**reviewed,
"hoxline": os.environ["HAWKINS_HOXLINE_EVENT_SHA"],
}
actual = sorted(path.name for path in root.iterdir() if (path / ".git").exists())
if actual != sorted(expected):
raise SystemExit(f"exact seven-repository checkout required; expected={sorted(expected)}, actual={actual}")
for name in expected:
sha = subprocess.check_output(
["git", "-C", str(root / name), "rev-parse", "HEAD"],
text=True,
).strip()
print(f"{name}={sha}")
if sha != immutable[name]:
raise SystemExit(
f"{name} checkout mismatch: expected {immutable[name]}, got {sha}"
)
PY

- name: Set up Python
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
with:
python-version: ${{ matrix.python-version }}

- name: Install package and test dependencies
- name: Install package and declared test dependencies
working-directory: org/hoxline
run: |
python -m pip install --upgrade pip
python -m pip install -e ".[test]"

- name: Run tests
run: python -m pytest
- name: Compile
working-directory: org/hoxline
run: python -B -m compileall src tests

- name: Reject retired tracked vocabulary
working-directory: org/hoxline
run: |
python -B - <<'PY'
from pathlib import Path
from hoxline.review_engine import verify_tracked_vocabulary

errors = verify_tracked_vocabulary(Path("."))
if errors:
raise SystemExit("\n".join(errors))
print("Tracked vocabulary verification: PASS")
PY

- name: Run unittest suite
working-directory: org/hoxline
run: python -B -m unittest discover -s tests

- name: Run full pytest suite including hostile replay cases
working-directory: org/hoxline
run: python -B -m pytest

- name: Passing example succeeds
- name: Generate Case Growth pair from exact seven checked sources
working-directory: org/hoxline
run: >-
python -B -m hoxline.cli case-growth index
--repo-root ..
--format json
--paired-output-base "${{ runner.temp }}/current-case-growth-index"

- name: Verify checked Case Growth pair
working-directory: org/hoxline
run: >-
python -B -m hoxline.cli case-growth verify
--repo-root ..
--snapshot examples/case-growth/current-case-growth-index.json

- name: Diff checked Case Growth pair
working-directory: org/hoxline
run: >-
python -B -m hoxline.cli case-growth diff
--repo-root ..
--snapshot examples/case-growth/current-case-growth-index.json
--format json

- name: Run expanded batch and verify complete replay
working-directory: org/hoxline
run: |
python -B -m hoxline review batch run \
--index examples/review/multi-artifact-review-index-v1.json \
--output "${{ runner.temp }}/hoxline-batch" \
--force
python -B -m hoxline review batch verify \
--run "${{ runner.temp }}/hoxline-batch/batch-machine-state.json"

- name: Run one-command reviewer demo
working-directory: org/hoxline
run: >-
python -B -m hoxline demo quickstart
--output "${{ runner.temp }}/hoxline-demo"
--force

- name: Passing Claim Firewall example succeeds
working-directory: org/hoxline
run: python -m claimfirewall scan examples/pass.md --policy policy/blocked_claims.yml

- name: Failing example fails
- name: Failing Claim Firewall example is rejected
working-directory: org/hoxline
run: |
if python -m claimfirewall scan examples/fail.md --policy policy/blocked_claims.yml; then
echo "Expected failing example to report blocked claims"
exit 1
fi
python - <<'PY'
import subprocess
import sys

result = subprocess.run(
[
sys.executable,
"-m",
"claimfirewall",
"scan",
"examples/fail.md",
"--policy",
"policy/blocked_claims.yml",
],
check=False,
)
if result.returncode != 1:
raise SystemExit(f"expected blocked example exit 1, got {result.returncode}")
PY

- name: Safe context docs succeed
working-directory: org/hoxline
run: python -m claimfirewall scan README.md CLAIM_BOUNDARY.md --policy policy/blocked_claims.yml

- name: JSON output is valid and contains findings
- name: Reject legacy product naming
working-directory: org/hoxline
run: |
set +e
python -m claimfirewall scan examples/fail.md --policy policy/blocked_claims.yml --format json > findings.json
status=$?
set -e
if [ "$status" -ne 1 ]; then
echo "Expected JSON scan to exit 1"
exit 1
fi
python -m json.tool findings.json > /dev/null
python - <<'PY'
import json
from pathlib import Path
data = json.loads(Path("findings.json").read_text())
if not data.get("findings"):
raise SystemExit("Expected JSON findings")
import re

pattern = re.compile(r"c[l]aimlint", re.IGNORECASE)
hits = []
for path in Path(".").rglob("*"):
if not path.is_file() or ".git" in path.parts:
continue
try:
text = path.read_text(encoding="utf-8")
except (OSError, UnicodeDecodeError):
continue
if pattern.search(text):
hits.append(path.as_posix())
if hits:
raise SystemExit(f"legacy product naming found: {hits}")
PY

- name: Old name search
- name: Verify no tracked drift
working-directory: org/hoxline
run: |
if rg -n "c[l]aimlint|C[l]aimlint|C[L]AIMLINT" .; then
echo "Old naming found"
exit 1
fi
git diff --check
test -z "$(git status --porcelain --untracked-files=no)"
8 changes: 4 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,9 +27,9 @@ python -B -m hoxline demo quickstart --output .hoxline/demo-runs/self-test --for
python -B -m hoxline demo verify --input .hoxline/demo-runs/self-test/run-summary.json
```

The command writes `.hoxline/demo-runs/<timestamp-or-demo-id>/` with `intake.json`, `evidence-graph.json`, `telemetry-contract-check.json`, `validation-result.json`, `synthetic-signal.json`, `enrichment.json`, `triage-summary.md`, `proofcard.json`, `proofcard.md`, `claim-authority.json`, `reviewer-pack.md`, and `run-summary.json`.
The command writes `.hoxline/demo-runs/<timestamp-or-demo-id>/` with `intake.json`, `evidence-graph.json`, `telemetry-contract-check.json`, `validation-result.json`, `controlled-test-signal.json`, `enrichment.json`, `triage-summary.md`, `proofcard.json`, `proofcard.md`, `claim-authority.json`, `reviewer-pack.md`, and `run-summary.json`.

What it proves: Hoxline can carry a synthetic HO-DET-010 fixture through intake, evidence graph, telemetry contract check, controlled validation, fixture-only signal simulation, enrichment, triage, ProofCard, Claim Authority, blocked claims, and reviewer packaging.
What it proves: Hoxline can carry a controlled-test HO-DET-010 fixture through intake, evidence graph, telemetry contract check, controlled validation, fixture-only signal simulation, enrichment, triage, ProofCard, Claim Authority, blocked claims, and reviewer packaging.

What it does not prove: live runtime behavior, public signal observation, public-safe status, production readiness, SOCaaS deployment, customer deployment, autonomous SOC operation, AI approval, analyst approval, final authorization, or case closure. The demo does not touch endpoints, users, groups, Wazuh, Splunk, Cribl, private infrastructure, ledgers, or website proof state.

Expand All @@ -46,7 +46,7 @@ python -B -m hoxline review verify --run .hoxline/runs/<run-id>/machine-state.js

The command writes `.hoxline/runs/<run-id>/` with `artifact-manifest.json`, stage outputs, `proofcard.json`, `proofcard.md`, `claim-authority.json`, `reviewer-pack.md`, `machine-state.json`, and `run-summary.json`.

What it proves: Hoxline can take a public sanitized synthetic artifact manifest, run deterministic local review stages, write replayable machine state, generate reviewer artifacts, and block unsupported claims.
What it proves: Hoxline can take a public sanitized controlled-test artifact manifest, run deterministic local review stages, write replayable machine state, generate reviewer artifacts, and block unsupported claims.

What it does not prove: live runtime behavior, public signal observation, public-safe status, production readiness, SOCaaS deployment, customer deployment, autonomous SOC operation, AI approval, analyst approval, final authorization, or case closure.

Expand Down Expand Up @@ -141,7 +141,7 @@ References are carried from `hawkinsoperations-platform#64` and `hawkinsoperatio

Hoxline also supports private runtime candidate review for artifacts whose source, telemetry contract, validation, private signal, packet verification, and scheduled collector inclusion have been established internally but are not public-safe proof.

Separate from the one-command fixture demo, HO-DET-010 also has private runtime-candidate context that is not published here. The public demo uses only synthetic fixture records and must not be confused with private runtime candidate evidence. HO-DET-010 remains `NOT_PUBLIC_SAFE`; human review is required; AI has no disposition authority; no public proof, ledger append, website proof promotion, production, customer, SOCaaS, fleet, analyst-approved, AI-approved, or case-closure claim is made.
Separate from the one-command fixture demo, HO-DET-010 also has private runtime-candidate context that is not published here. The public demo uses only controlled-test fixture records and must not be confused with private runtime candidate evidence. HO-DET-010 remains `NOT_PUBLIC_SAFE`; human review is required; AI has no disposition authority; no public proof, ledger append, website proof promotion, production, customer, SOCaaS, fleet, analyst-approved, AI-approved, or case-closure claim is made.
## Claim Firewall

Claim Firewall is the first Claim Authority enforcement capability inside Hoxline.
Expand Down
8 changes: 4 additions & 4 deletions docs/demo/HOXLINE_ONE_COMMAND_REVIEWER_DEMO_V0.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ ai_disposition_authority: false

## Purpose

This demo lets a reviewer clone Hoxline, run one command from the repo root, and see the governed ProofOps loop in about 30 seconds. It uses a bundled synthetic HO-DET-010 fixture for a local Administrators membership-change pattern. It does not create users, change groups, touch endpoints, connect to Wazuh, publish private evidence, or claim live runtime proof.
This demo lets a reviewer clone Hoxline, run one command from the repo root, and see the governed ProofOps loop in about 30 seconds. It uses a bundled controlled-test HO-DET-010 fixture for a local Administrators membership-change pattern. It does not create users, change groups, touch endpoints, connect to Wazuh, publish private evidence, or claim live runtime proof.

## Command

Expand All @@ -37,7 +37,7 @@ The command writes `.hoxline/demo-runs/<timestamp-or-demo-id>/` with:
- `evidence-graph.json`
- `telemetry-contract-check.json`
- `validation-result.json`
- `synthetic-signal.json`
- `controlled-test-signal.json`
- `enrichment.json`
- `triage-summary.md`
- `proofcard.json`
Expand All @@ -64,7 +64,7 @@ The command writes `.hoxline/demo-runs/<timestamp-or-demo-id>/` with:

## Supported Artifact

The demo supports `HO-DET-010` with a synthetic local Administrators membership-change fixture:
The demo supports `HO-DET-010` with a controlled-test local Administrators membership-change fixture:

- positive fixture: `examples/demo/ho-det-010-safe-fixture.json`
- negative fixture: `examples/demo/ho-det-010-safe-negative-fixture.json`
Expand All @@ -73,7 +73,7 @@ The telemetry contract represents Windows Security EventChannel assumptions for

## What It Proves

- Hoxline can generate the reviewer path locally from synthetic fixtures approved for public demo use.
- Hoxline can generate the reviewer path locally from controlled-test fixtures approved for public demo use.
- The demo produces structured records for intake, graph linkage, telemetry assumptions, validation, signal simulation, enrichment, triage, ProofCard, Claim Authority, and reviewer packaging.
- Claim Authority allows bounded demo wording and blocks unsupported public claims.

Expand Down
Loading
Loading