Hiro development journal

Adding internet-observation review to Hiro's benchmark page

Validated and published Machine-readable JSON

Executive summary

Restored Hiro's stopped API service and added a dedicated read-only Internet observations view to the Evaluation Observatory benchmark page.

The view now lists all three snapshots from the first low-budget Phase 1 shadow session, including source, timestamp, HTTP result, retrieval budget usage, sanitization results, packet and content hashes, and expandable sanitized text.

Every record is reverified against its SHA-256 companion before the API exposes it. A packet that fails integrity validation is counted but excluded from review.

Focused dashboard and observation validation passed 63 tests, and the complete Hiro suite passed all 383 tests before the service restart.

The observation capture policy remains disabled, the observation sentinel and Stage 6 sentinel remain present, and dashboard visibility grants no case-conversion, promotion, deployment, or Stage 6 authority.

Work completed

Verified observation API

Completed
  • Added a read-only evaluation API route that discovers timestamped snapshot packets beneath the configured runtime snapshot root.
  • The route verifies each packet's companion SHA-256, sanitized-content SHA-256, schema, untrusted-evidence marker, and zero-authority boundary through the existing snapshot verifier.
  • The response exposes sanitized text and review metadata only. Raw response bodies, cookies, credentials, and local snapshot filesystem paths are not returned.
  • The response reports total, verified, and rejected packet counts while keeping promotion_authorized false.

Benchmark review interface

Completed
  • Added an Internet observations tab alongside Overview, Nightly, Autonomous changes, Performance, Runs, Compare, and Lineage.
  • The view summarizes captured snapshots, verified integrity, rejected packets, total retrieved bytes, capture-policy state, and promotion authority.
  • Each collapsed record shows its source and status. Expanding it reveals request metadata, content type, sanitizer actions, injection indicators, hashes, authority, and scroll-bounded sanitized content.
  • All external text and metadata are escaped before insertion into the page, so sanitized evidence remains data rather than executable markup or instructions.

Service restoration

Completed
  • Diagnosed the loading failure as a stopped Hiro API origin while the existing remote-access tunnel remained active.
  • After user authorization, started Hiro through its pinned hidden launcher without changing the separate no-automatic-recovery marker.
  • Verified successful listeners for the main API, local HTTP API, and loopback-only Evaluation Observatory origin.
  • Verified that the public benchmark address reaches its existing access-control boundary and that the local origin now returns the benchmark page and observation API successfully.

Decisions and reasoning

Validation and evidence

CheckStatusResult
Focused dashboard and observation tests passed All 63 focused tests passed, covering dashboard authentication boundaries, autonomous candidates, router performance, observation sanitization, snapshot verification, path restrictions, and the new review endpoint and page contract.
Complete Hiro suite passed All 383 tests passed in 119.76 seconds before the service was restarted.
Live observation API passed The restored loopback API returned three captured snapshots, three verified snapshots, zero integrity failures, 81,403 total retrieved bytes, capture disabled, and promotion authority false.
Browser-rendered benchmark page passed Browser inspection confirmed the new tab renders all three sources, the aggregate safety cards, expandable metadata and sanitized content, exact hashes, and no browser console errors.
Service listeners and remote boundary passed The API is listening on its three expected ports; the loopback benchmark origin returns HTTP 200, and the remote benchmark address reaches the configured access login boundary.
Implementation commit passed The read-only snapshot review API and benchmark UI were committed at 397fa21 on Hiro's existing development branch.

Current state

Next steps