{
  "schemaVersion": 2,
  "date": "2026.08.06",
  "publishedAt": "2026-08-06T00:14:36-07:00",
  "timeZone": "America/Los_Angeles",
  "title": "Completing Hiro's first low-budget internet-observation shadow session",
  "publicationStatus": "Validated and published",
  "executiveSummary": [
    "Configured Hiro's Phase 1 observation policy for three explicitly approved public sources: one exact IANA control page, the Python 3 documentation tree, and one exact PyPI Simple Index project page.",
    "Added host-bound exact-URL and path-prefix enforcement so approval of a hostname no longer authorizes unrelated paths on that host. Request, elapsed-time, and cumulative-byte budgets now persist across every capture made by one observer session.",
    "Passed 55 focused adversarial tests and the complete 382-test Hiro suite before making any public request.",
    "The authorized shadow session then completed exactly three direct, read-only GET requests: all returned HTTP 200, no redirect occurred, and 81,403 response bytes were retrieved in 0.754 seconds. Each response was sanitized and frozen with a verified SHA-256 companion.",
    "The observation lane was re-disabled immediately after the session. Stage 6 remained disabled, and the session granted no promotion, deployment, credential, or state-changing authority."
  ],
  "workstreams": [
    {
      "title": "Host-bound path policy",
      "status": "Completed",
      "details": [
        "Introduced separate exact-URL and URL-prefix rules that are validated against the exact-host allowlist and HTTPS-only port policy.",
        "Configured the IANA reserved-domain page and the PyPI httpx Simple Index page as exact URLs, with the Python 3 documentation tree as the single approved prefix.",
        "Rejected encoded, non-ASCII, doubled-slash, backslash, and dot-segment paths so a permitted prefix cannot be used to reach a different server-normalized location.",
        "Kept the checked-in policy disabled while retaining the reviewed Phase 1 host and path configuration for later controlled sessions."
      ]
    },
    {
      "title": "Session-wide resource limits",
      "status": "Completed",
      "details": [
        "Changed the observer's request and response-byte accounting from per-capture counters to shared session counters.",
        "Set the Phase 1 policy to three total request attempts, zero redirects, a 20-second total elapsed-time ceiling, an eight-second per-request timeout, and a one-megabyte cumulative response ceiling.",
        "Added offline coverage proving that multiple captures consume the same request and download budgets and that a later capture fails closed after exhaustion."
      ]
    },
    {
      "title": "First public shadow session",
      "status": "Completed",
      "details": [
        "Used one shared observer instance for the three approved URLs, with no cookies, authentication, proxy inheritance, query strings, uploads, or state-changing methods.",
        "The session used three of three request attempts, followed no redirects, downloaded 81,403 of 1,000,000 permitted bytes, and completed in 0.753781 seconds.",
        "All three responses returned HTTP 200. Sanitization removed active HTML elements, found no credential-shaped values requiring redaction, detected no configured prompt-injection indicator, and did not truncate any snapshot.",
        "The three immutable snapshot packets, their individual companions, and a separate read-only session manifest and companion were independently reverified after the observation sentinel was restored."
      ]
    }
  ],
  "decisions": [
    "Use exact URLs for the IANA and PyPI targets because no broader path authority is needed.",
    "Use a path prefix only for the Python 3 documentation tree, where multiple documentation pages may become useful in later sessions.",
    "Count every redirect attempt against the same session request budget even though the first session permits zero redirects.",
    "Retain the sanitized snapshots as untrusted observation evidence only; do not convert them into evaluation cases without affirmative human review and explicit assertions.",
    "Restore the observation DISABLED sentinel after the one-use session and leave the checked-in policy enabled false.",
    "Do not enable Stage 6 or authorize candidate promotion as part of internet observation."
  ],
  "validation": [
    {
      "check": "Focused offline adversarial suite",
      "status": "passed",
      "result": "All 55 internet-observation tests passed before public access. Coverage includes host/path binding, noncanonical path denial, private-network denial, redirect revalidation, pinned-address TLS, shared budgets, sanitization, tamper detection, human review, and frozen-snapshot replay equality."
    },
    {
      "check": "Complete Hiro suite",
      "status": "passed",
      "result": "All 382 tests passed in 138.08 seconds before the shadow session."
    },
    {
      "check": "Live request boundary",
      "status": "passed",
      "result": "Exactly three approved GET requests completed with three HTTP 200 responses, zero redirects, no query strings, and cumulative usage below every configured limit."
    },
    {
      "check": "Snapshot and session integrity",
      "status": "passed",
      "result": "All three timestamped snapshot packets matched their SHA-256 companions and sanitized-content hashes. The session manifest matched companion SHA-256 e44fc285a136ab0881a5fe30d41838b1da761181c3d84b31f6922906ec36e975."
    },
    {
      "check": "Authority and stop state",
      "status": "passed",
      "result": "The observation sentinel was restored, the checked-in policy remains disabled, Stage 6 DISABLED remained present, and every evidence packet records zero credential, state-change, promotion, and Stage 6 authority."
    },
    {
      "check": "Hiro implementation commit",
      "status": "passed",
      "result": "The path-scoped Phase 1 implementation and tests were committed at 6277c9c on the existing development branch."
    }
  ],
  "currentState": [
    "Phase 1 hosts and paths are configured in the checked-in policy, which remains enabled false.",
    "The observation DISABLED sentinel and Stage 6 DISABLED sentinel are present.",
    "Three sanitized public snapshots and one session manifest are retained locally as read-only, tamper-evident runtime evidence.",
    "No snapshot has been converted into a repeatable evaluation case, and no baseline-versus-candidate replay has been run from this live evidence.",
    "No candidate was promoted, deployed, merged, or used to restart a service."
  ],
  "limitations": [
    "This was a short connectivity and control-boundary shadow session, not evidence that autonomous internet observation is ready for continuous unattended operation.",
    "The retrieved material has been sanitized but remains untrusted external evidence until a human reviews its relevance and defines repeatable assertions.",
    "Only one page on each approved host was requested, so this session does not characterize broader reliability or content variability within the Python documentation prefix.",
    "The current policy deliberately excludes query parameters, redirects, downloads, authentication, interactive pages, and general web discovery."
  ],
  "nextSteps": [
    "Review the three sanitized snapshots on Hiro's benchmark or evidence interface without granting their contents instructional authority.",
    "Select only useful real-world observations for affirmative human review and conversion into repeatable frozen-snapshot evaluation cases.",
    "Prove the baseline and candidate consume the identical selected snapshot hash before using any case as evaluation evidence.",
    "Keep future sessions similarly small until several reviewed sessions show stable snapshot integrity and useful failure-case conversion.",
    "Continue deferring GitHub and National Weather Service sources until their additional content, rate-limit, identification, and media-type requirements are explicitly implemented and tested."
  ],
  "disclosureNote": "This public entry contains no credentials, private held-out cases, personal data, raw retrieved page content, private network data, or actionable details about unresolved security weaknesses."
}
