Hiro development journal

Starting Hiro's finite recurring internet-observation probation

Validated and published Machine-readable JSON

Executive summary

Implemented a finite unattended observation probation that can run one three-request read-only cycle per Pacific day while Stage 6 remains disabled.

The probation is pinned to an exact clean Hiro Git commit, capped at seven total attempts, separated by at least 20 hours, and designed to restore the observation stop sentinel after attempt seven. Infrastructure failures count toward the cap.

Each frozen snapshot now receives a deterministic source-specific probe through Hiro's local tool-free evaluator. Only a reproducible baseline failure creates a pending case proposal and Telegram review alert; a passing observation requires no action.

All 79 focused adversarial tests and the complete 394-test Hiro suite passed before public access. Cycle 1 then made exactly three approved GET requests, froze three verified snapshots, and passed all three offline probes with no proposal.

The probation remains in progress at cycle 1 of 7. No candidate change, approved case, promotion, deployment, or Stage 6 action resulted from this cycle.

Work completed

Finite fail-closed scheduler

Completed
  • Added a runtime-only probation authorization separate from the checked-in disabled-by-default policy and pinned it to Hiro commit f5b2d292aed6a52efd74ae1a5683369998eb062b.
  • Limited the probation to seven total attempts, one attempt per Pacific calendar day at 07:30, and a minimum 20-hour interval.
  • Required a clean pinned Git tree and the Stage 6 DISABLED sentinel before every cycle. Any source drift, policy mismatch, missing stop sentinel, overlapping run, or integrity failure stops the cycle before networking.
  • Counted infrastructure failures toward the seven-attempt limit so external instability cannot silently extend the probation. The seventh attempt restores the observation stop sentinel.

Deterministic failure discovery

Completed
  • Added one checked-in deterministic probe for each Phase 1 source: extract IANA's two example domains, select the highest Python series explicitly labeled stable, and select the latest stable httpx release while excluding development builds.
  • Expected values are derived by source-specific deterministic code from the frozen sanitized snapshot; the model does not grade its own answer.
  • Each probe uses Hiro's local tool-free evaluator with no browsing, shell, search, memory, history, or remote fallback, and retains the exact snapshot-content hash in its result.
  • Passing probes remain observation evidence only. A failed probe freezes a pending proposal containing the finding, prompt, assertions, baseline response, failure evidence, snapshot hashes, zero-authority declaration, and companion SHA-256.

Review and notification boundary

Completed
  • Added a Pending evaluation case proposals panel to the Internet observations benchmark view and changed the approvals-pending count to reflect verified proposals rather than raw snapshots.
  • The dashboard displays probation progress, next run time, per-snapshot review state, and a clear explanation that proposal approval authorizes frozen offline case creation and replay only.
  • Pending case proposals reuse the durable Telegram review outbox. Discoveries between 23:00 and 06:59 Pacific are held until 07:00, and proposal IDs are deduplicated.
  • No notification was queued or sent in cycle 1 because all baseline probes passed.

First recurring cycle

Completed
  • Cycle 1 made exactly one approved GET request to each of the existing IANA, Python documentation, and PyPI httpx targets, with zero redirects and no credentials, queries, uploads, or state-changing methods.
  • The cycle downloaded 82,014 bytes under the one-megabyte cumulative limit and froze three timestamped sanitized packets with independently verified packet and content hashes.
  • The IANA probe returned example.com, example.org; the Python probe returned 3.14; and the PyPI probe returned 0.28.1. All responses passed their deterministic assertions and recorded no tool use.
  • The session froze as completed_read_only_cycle with companion SHA-256 e7716fc0608b4967a8b28f11d3bdaaa0900d44f2816f166e6b7e349d52f854ae.

Decisions and reasoning

Validation and evidence

CheckStatusResult
Focused adversarial suite passed All 79 focused tests passed, covering deterministic oracle behavior, prerelease exclusion, finite attempt caps, same-day and minimum-interval guards, missing Stage 6 stop state, proposal tampering, overlapping scheduler runs, dashboard contracts, and Telegram quiet hours.
Complete Hiro suite passed All 394 tests passed in 117.29 seconds before runtime authorization or public requests.
Cycle 1 network boundary passed Exactly three approved HTTPS GETs returned HTTP 200 with zero redirects and 82,014 cumulative response bytes. No credential, query, upload, login, or state-changing action occurred.
Cycle 1 deterministic probes passed All three local tool-free probes passed with expected answers and no recorded tool use; zero case proposals and zero notifications resulted.
Frozen session integrity passed The session and every snapshot independently verify against their SHA-256 companions; the session companion is e7716fc0608b4967a8b28f11d3bdaaa0900d44f2816f166e6b7e349d52f854ae.
Live service and dashboard passed Hiro restarted on the pinned implementation and the rendered page shows six verified snapshots, probation 1/7, next run August 7 at 07:30 Pacific, zero pending approvals, and no promotion authority.
Journal generation and frontend build passed The timestamped-entry unit tests passed, 75 journal pages and aliases validated, and the production frontend build completed successfully.

Current state

Next steps