Hiro development journal

Implementing and benchmarking Hiro Stage 6A shadow decisions

Validated and published Machine-readable JSON

Executive summary

Implemented Hiro's Stage 6A shadow-only decision engine and ran the required 30-decision allow/deny benchmark without enabling automatic mutation.

The engine reads the disabled draft policy, classifies hypothetical evidence-only promotions, and writes only process-safe append-only SQLite decisions and simulated phase events. It has no Git, service, scheduler, deployment, candidate-materialization, or active-branch operation.

The frozen campaign completed 30 valid externally labeled decisions with 30 correct classifications: five hypothetical allows and 25 denials, for 100 percent accuracy with zero false allows and zero false denies.

Five controlled interruption boundaries resumed idempotently without duplicate events, and four competing child processes converged on one durable decision and five events.

Stage 6 remains disabled. The host-level persistent disable sentinel is present, policy status remains draft_disabled with enabled false, Git HEAD was unchanged, and automatic promotion readiness remains false.

Work completed

Shadow-only policy evaluator

Implemented and passed
  • Added a standalone evaluator that accepts normalized replay manifests and computes would-allow, would-deny, or invalid-infrastructure outcomes without consulting the externally supplied expected label.
  • The evaluator refuses any policy that is not a disabled draft or that grants active-branch or runtime mutation authority.
  • It validates user-bound policy identity, enablement timing, repository and branch identity, exact base revision, worktree state, leases, rate limits, cooldowns, both kill switches, evidence completeness, packet integrity, and restart/external-action declarations.
  • It enforces literal add-only paths, regular nonexecutable UTF-8 files, count/size/line limits, opportunity-key binding, Python AST restrictions for regression tests, deterministic JSONL structure, and safe documentation content.

Append-only decision and transition ledger

Implemented and passed
  • Added SQLite decision and phase-event tables protected by no-update and no-delete triggers.
  • Decision identity is bound to a canonical input SHA-256. Exact retries return the existing record; reuse with different evidence is rejected.
  • Five shadow phase events represent future preflight, staging, pre-fast-forward, post-fast-forward, and probation boundaries. Every event is explicitly marked simulation-only with zero mutation, restart, or external action.
  • A real four-process contention test showed all writers returning the same classification while the ledger retained one decision and five unique events.

Externally labeled 30-decision benchmark

Passed
  • Created exactly 30 deterministic replay cases: five allowed evidence-only shapes and 25 denied operation, path, content, repository-state, authorization, concurrency, rate, or integrity cases.
  • Denied probes covered modification, deletion, rename, mode change, symlink, binary content, traversal, policy self-modification, stale base, dirty worktree, expired enablement, lease collision, rate limit, both kill switches, packet tampering, submodule, file-count overflow, runtime path, restart, external action, unsafe test code, invalid JSONL, dependent judging evidence, and active probation.
  • The evaluator classified all 30 correctly: five would-allow and 25 would-deny, with zero false allows, zero false denies, and no infrastructure exclusions.
  • The durable ledger contains 30 decisions and 150 unique decision/event pairs, exactly five events per decision.

Interruption and idempotency exercise

Passed
  • Independently interrupted one otherwise eligible decision after each of the five shadow phase boundaries.
  • Every retry resumed from append-only evidence, completed with the same would-allow result, and retained exactly one event per phase.
  • Completed-decision reuse returned the frozen decision without adding events, while changed evidence under an existing decision identifier was rejected.

Disabled-state preservation

Passed
  • Created the persistent Stage 6 DISABLED sentinel with a plain statement that only shadow evaluation is allowed.
  • The policy remains draft_disabled and enabled false; both shadow and evidence-only active-branch mutation fields remain false.
  • The benchmark recorded zero active-branch mutations, promotions, service restarts, schedule changes, or external actions, and the repository HEAD stayed unchanged.

Decisions and reasoning

Validation and evidence

CheckStatusResult
Focused Stage 6 policy and shadow suite passed 18 tests passed in 3.79 seconds on the final rerun.
Repository-wide regression suite passed 303 tests passed in 149.54 seconds.
Thirty-decision classification campaign passed 30 of 30 valid decisions were correct: five hypothetical allows and 25 denials, with 100 percent accuracy, zero false allows, zero false denies, and zero infrastructure exclusions.
Append-only ledger audit passed The durable ledger contained 30 decisions, 150 events, and 150 unique decision/event pairs; no update or delete is permitted by its triggers.
Five interruption boundaries passed Preflight, staging, pre-fast-forward, post-fast-forward, and probation-boundary interruptions all resumed exactly without duplicate events.
Competing-process logging passed Four child processes concurrently evaluated the same input and converged on one durable decision and five phase events.
Frozen packet integrity passed Benchmark packet SHA-256 00400ec385a98a8c5392b57b23db7ddf23278085128adc9da80036721db3c5e1 verified.
Mutation and activation boundary passed Policy and host sentinel remained disabled; Git HEAD was unchanged; active mutations, promotions, restarts, schedule changes, and external actions were all zero.
Hiro journal generation and frontend build passed Timestamped-entry unit tests passed; the generator produced and validated 62 journal pages, and the TypeScript and Vite production build completed successfully.

Current state

Next steps