Hiro development journal

Building Hiro's controlled internet-observation lane

Validated and published Machine-readable JSON

Executive summary

Reconciled Hiro's extensive existing working state into a clean, recoverable baseline commit and added local annotated pins for both the pre-observation baseline and the completed observation implementation.

Implemented a disabled-by-default, exact-host, HTTPS-only observation client that supports only GET and HEAD, pins connections to prevalidated public IP addresses, revalidates every redirect, and enforces cumulative request, time, byte, redirect, port, query, and content limits.

Implemented active-content removal, credential-shaped redaction, prompt-injection boundary handling, timestamped tamper-evident snapshot packets, mandatory human review before case creation, and paired baseline/candidate replay bound to the same frozen snapshot hash.

The focused offline safety suite passed 62 tests and the complete Hiro suite passed all 374 tests. The implementation remains inactive with an empty allowlist, disabled policy, local observation DISABLED sentinel, zero snapshots, no promotion authority, and Stage 6 still disabled.

Work completed

Clean pinned Hiro baseline

Completed
  • Audited 167 modified and untracked source, documentation, configuration-example, launcher, and test files accumulated across prior Hiro sessions.
  • Excluded the ignored local environment, credentials, databases, logs, runtime state, generated benchmark data, pytest scratch directories, and a downloaded local tunnel executable.
  • Scanned staged content for common credential and private-key patterns before committing; no matching secret material was found.
  • Committed the reconciled state as dbcf4a5391ef7438c8f78f9a26c7c1e955a46e51 and created local annotated tag hiro-internet-observation-baseline-20260805. No existing source work was discarded.

Read-only network authority

Implemented but disabled
  • The versioned policy permits only GET and HEAD over HTTPS to exact fully qualified hostnames. Wildcards, IP literals, URL credentials, fragments, query parameters, nonstandard ports, and non-text response types are denied during probation version 1.
  • Every DNS answer must be globally routable. Mixed public/private results fail closed, covering loopback, private, link-local, reserved, multicast, unspecified, and other non-global IPv4 and IPv6 ranges.
  • The production transport connects directly to the validated IP while preserving the approved hostname for TLS certificate verification and the Host header, eliminating a normal second DNS lookup between validation and connection.
  • Redirects are followed only after a fresh host, address, policy, and budget check. Cookies, Authorization headers, proxy inheritance, compression, uploads, posting, purchases, and state-changing methods are absent.

Budgets and emergency controls

Implemented
  • The client enforces independent maximums for total requests, cumulative downloaded bytes across redirects, total elapsed time, per-request timeout, redirects, response Content-Length, content type, port, and method.
  • The policy must be explicitly enabled, must contain at least one approved exact domain, and must not have the local internet-observation DISABLED sentinel present before any request can begin.
  • The shipped policy remains disabled with an empty allowlist, and the local observation sentinel remains present.
  • Stage 6 has a separate DISABLED sentinel and remains unchanged. No observation component contains integration, deployment, or promotion authority.

Sanitized frozen evidence

Implemented
  • The required capture entrypoint retrieves one page and immediately sanitizes and freezes it; the CLI does not expose an unfrozen successful capture workflow.
  • HTML scripts, styles, forms, inputs, embedded documents, active objects, and similar elements are removed. Credential-named JSON fields, credential-shaped values, control characters, and attempted snapshot boundary markers are redacted or neutralized.
  • Each timestamped packet retains only sanitized text, safe response headers, redirect and address provenance, policy and content hashes, and explicit declarations that credentials, state changes, promotion, and Stage 6 authority were absent.
  • The raw body is not persisted; its length and SHA-256 are recorded. The packet and sanitized content have independent SHA-256 checks, read-only file permissions, and verification before reuse.

Reviewed replay cases

Implemented
  • Retrieval never creates a pass/fail case automatically. A reviewer must affirm the finding and supply the task and explicit assertions.
  • The case provider verifies the snapshot packet companion, sanitized content hash, packet hash, embedded snapshot text, untrusted marker, and frozen case companion.
  • The isolated evaluator treats snapshot content as untrusted evidence and refuses role labels, tool requests, links, or instruction overrides inside the snapshot boundary.
  • The paired replay runner independently reloads baseline and candidate case sets, proves identical sanitized snapshot hashes before execution, and verifies that both reports retain the same binding afterward.

Decisions and reasoning

Validation and evidence

CheckStatusResult
Focused internet-observation and evaluator safety suite passed 62 tests passed in 1.58 seconds using injected DNS and HTTP fixtures. Coverage includes disabled controls, exact-host policy, forbidden methods and URL forms, private IPv4/IPv6, mixed DNS, address pinning and hostname TLS, redirect and DNS revalidation, cumulative limits, active-content stripping, secret redaction, injection markers, tamper detection, mandatory review, and identical baseline/candidate snapshot bindings.
Complete Hiro test suite passed 374 tests passed in 143.61 seconds after converting a legacy sports performance test from a live external request to its existing mocked HTTP seam.
External-request accounting passed with disclosed legacy event The new observation client made no public request and produced zero snapshots. During the first broad test attempt, an unrelated pre-existing sports test performed one read-only unauthenticated ESPN request after the focused adversarial suite had already passed; it exceeded its latency threshold. That test was made hermetic before the final full-suite run.
Repository and disable state passed Implementation commit ffd6eba32308114b69da70921f84591d0089dc50 is clean and locally tagged hiro-internet-observation-ready-20260805. Policy enabled is false, approved-domain count is zero, the observation DISABLED sentinel exists, snapshot count is zero, and Stage 6 DISABLED exists.
Hiro journal generation and frontend build passed The timestamped-entry test and production frontend build completed successfully before publication.

Current state

Next steps