Hiro development journal

Exercising Hiro Stage 6 rollback and probation mechanics in sealed fixtures

Validated and published Machine-readable JSON

Executive summary

Implemented Hiro's future Stage 6 transaction, canary, probation, rollback, and emergency-stop mechanics behind a controller that is structurally restricted to marked external fixture repositories.

The controller refuses Hiro's repository, requires a tracked fixture marker and shadow branch, requires the persistent host disable sentinel, rejects the activation environment value, and accepts only candidates classified as hypothetical would-allow by the disabled shadow policy.

Three sealed-fixture rollback drills met their expected outcomes: two additive Git reverts restored exact base trees, including one post-fast-forward interruption/resume, and an overlapping-state drill entered emergency stop without attempting an unsafe revert.

A separate retained fixture passed an immediate canary and five time-compressed probation checkpoints representing 0, 15, 60, 360, and 1,440 minutes.

Stage 6 remains disabled. Hiro's revision did not change, and production promotions, restarts, schedule changes, and external actions remained zero.

Work completed

Forced-shadow fixture authority

Implemented and passed
  • The controller rejects any fixture path that overlaps Hiro's repository and requires the external repository root to match the request exactly.
  • A tracked fixture marker with a bounded identity and a target branch using the shadow/stage6 prefix are mandatory.
  • The host persistent DISABLED sentinel must exist, while an exact activation environment value causes immediate refusal.
  • Candidate eligibility is rechecked through the Stage 6A evaluator, and its decision must explicitly retain zero active-branch mutation authority.

Transaction and coordination mechanics

Implemented and passed
  • Added an atomic SQLite fixture lease with live-owner refusal, same-owner renewal, expiration, and stale-owner takeover.
  • Each candidate is materialized and committed in a separate external worktree directly above the sealed base. Paths and exact UTF-8 contents are reverified before the fixture target can fast-forward.
  • The target operation is fast-forward only. Resume accepts a non-candidate HEAD only when a prior immutable fast-forward event exists and the drill explicitly exercises overlap handling.
  • Events and outcomes are append-only, request-hash bound, idempotent, and protected against update or deletion. Frozen disk packets must match both their SHA-256 companions and the append-only ledger payload.

Canary, probation, and rollback

Implemented and passed in fixtures
  • The controller runs an immediate explicit pytest canary after fast-forward. A failure triggers Git revert only when fixture HEAD still equals the exact candidate revision.
  • Rollback verifies that the post-revert tree equals the sealed base and reruns the canary to confirm recovery before freezing the outcome.
  • Passing candidates run five checkpoint test groups at the designed probation offsets. This campaign compressed time and therefore does not count as a real 24-hour observation.
  • Any overlapping HEAD enters emergency stop, records that no automatic revert was attempted, freezes evidence, and ends mutation.

Three rollback drills

Passed
  • Clean rollback drill: a real fixture fast-forward caused its incompatible canary to fail; an additive revert restored an exact base-equivalent clean tree.
  • Interrupted rollback drill: execution stopped after fixture fast-forward, resumed the same candidate revision without duplicate candidate or event, then failed canary and reverted to the exact base tree.
  • Overlap drill: a separate commit modified the promoted fixture path after fast-forward. The controller detected the changed HEAD, attempted no revert, and froze an emergency-stop outcome while preserving both commits.

Retained probation rehearsal

Passed with compressed time
  • A fourth fixture passed its immediate canary and all five monitoring checkpoints.
  • The outcome retained the candidate only in that sealed fixture and explicitly marked probation_time_compressed true.
  • No claim of real 24-hour operational stability was made.

Decisions and reasoning

Validation and evidence

CheckStatusResult
Focused Stage 6 suite passed 26 tests passed in 20.75 seconds, including fixture authority, activation refusal, exact rollback, interruption resume, overlap emergency stop, retained checkpoints, stale-lease recovery, append-only enforcement, the 30-decision classifier, and process-safe shadow logging.
Repository-wide regression suite passed 311 tests passed in 150.06 seconds.
Clean history-preserving rollback passed The fixture history contains base, candidate, and revert commits; its final tree matches the base and the worktree is clean.
Post-fast-forward interruption recovery passed Resume reused one candidate revision and one fast-forward event, then produced one revert and an exact base-equivalent tree.
Overlapping-state emergency stop passed The fixture retained base, candidate, and overlapping commits; the outcome recorded emergency stop and zero automatic revert attempts.
Time-compressed probation rehearsal passed Immediate canary plus all five checkpoint groups passed; the outcome explicitly records compressed time.
Campaign ledger and packet integrity passed The campaign packet SHA-256 verified; 33 transaction events were all unique, and four append-only outcomes were frozen.
Hiro isolation passed Hiro HEAD remained c9148f1ec4cf9164e4256cc3ce93efdd6794282a before and after. Active Hiro mutations, production promotions, restarts, schedule changes, and external actions were zero.
Hiro journal generation and frontend build passed Timestamped-entry unit tests passed; the generator produced and validated 63 journal pages, and the TypeScript and Vite production build completed successfully.

Current state

Next steps