{
  "schemaVersion": 2,
  "date": "2026.08.06",
  "publishedAt": "2026-08-06T08:28:00-07:00",
  "timeZone": "America/Los_Angeles",
  "title": "Accelerating Hiro's probation with rotating official sources",
  "publicationStatus": "Validated and published",
  "executiveSummary": [
    "Reconfigured the remaining finite internet-observation probation from a 20-hour repeated-source cadence to a minimum six-hour cadence using seven fixed rotations of exact official URLs.",
    "The total probation remains capped at seven attempts and every cycle remains limited to three read-only HTTPS requests, 20 seconds, one megabyte, and zero redirects. Stage 6 and automatic promotion remain disabled.",
    "Added deterministic probes for Python releases, PEP metadata, RFC reserved names, and selected PyPI package indexes. The evaluator receives a compact evidence projection while every result remains cryptographically bound to the full frozen snapshot.",
    "Offline validation passed all 77 focused observation, scheduler, and dashboard tests and the complete 397-test Hiro suite. No new public request was made during implementation.",
    "Hiro is clean and pinned to commit e6c3672728668014faea1d288a92b08949d283f0. The next three-source rotation becomes eligible at 2026-08-06T13:47:39-07:00."
  ],
  "workstreams": [
    {
      "title": "Fixed source rotations",
      "status": "Completed",
      "details": [
        "Defined seven immutable three-target rotations across exact IANA, Python documentation, Python source release, PEP, RFC Editor, and selected PyPI Simple Index URLs.",
        "The first rotation preserves the already completed IANA, Python documentation, and PyPI httpx evidence. The next rotation uses Python source releases, PEP 0, and RFC 2606.",
        "Later rotations cover pydantic, pytest, and fastapi package metadata; PEP 8 and PEP 703 metadata; and repeated stable controls without expanding beyond the approved official domains.",
        "The runtime policy lists every exact target or the existing narrow Python documentation prefix. It grants no login, credential, upload, posting, purchase, query-string, or state-changing authority."
      ]
    },
    {
      "title": "Accelerated finite cadence",
      "status": "Completed",
      "details": [
        "Changed the minimum interval from 20 hours to six hours while retaining the original seven-attempt finite cap.",
        "Added a separate hard ceiling of four attempts per Pacific calendar day. The 07:30 local start boundary and six-hour spacing normally produce no more than three attempts in a day, while the independent ceiling remains a fail-closed backstop.",
        "The dashboard now reports the next rotation number and its source domains alongside the verified next eligible time.",
        "Infrastructure failures still count toward the seven attempts and the observation stop sentinel is still restored after the final attempt."
      ]
    },
    {
      "title": "Deterministic source probes",
      "status": "Completed",
      "details": [
        "Added deterministic extraction for the latest stable Python source release, explicitly excluding alpha, beta, and release-candidate entries.",
        "Added deterministic Status and Type extraction for PEP 0, PEP 8, and PEP 703, plus ordered extraction of RFC 2606's four reserved top-level names.",
        "Generalized the PyPI probe to derive the latest stable version for httpx, pydantic, pytest, and fastapi while excluding development and prerelease artifacts.",
        "Each probe derives its expected assertion from the full sanitized snapshot, sends only a small relevant projection to the local tool-free evaluator, and records SHA-256 bindings for both the full snapshot and projection."
      ]
    },
    {
      "title": "Recurring evaluator integrity",
      "status": "Completed",
      "details": [
        "Offline second-cycle testing revealed that reusing one immutable evaluator manifest identity across multiple probation cycles would cause a later cycle to fail closed before evaluation.",
        "Assigned each finite cycle its own immutable evaluation identity while preserving the same pinned Git baseline in every manifest.",
        "Added test coverage proving that cycle two selects rotation two, freezes its target URLs and rotation index, uses three requests, and completes all three deterministic probes.",
        "Existing cycle-one evidence remains immutable and valid; no ledger, snapshot, or prior result was rewritten."
      ]
    }
  ],
  "decisions": [
    "Use different official sources to improve evidence diversity rather than rapidly re-fetching the same three pages.",
    "Use a six-hour interval as the accelerated safety/evidence balance, with an independent maximum-four-per-day backstop.",
    "Keep exactly three public requests per cycle even though the overall allowlist now contains more targets.",
    "Project large sanitized pages to small task-relevant evidence for local evaluation while retaining the full immutable snapshot as the canonical source binding.",
    "Preserve proposal-only behavior: only a failed baseline probe may create review work, and any later approval authorizes offline case creation and replay only.",
    "Do not enable Stage 6, promotion, deployment, or any state-changing internet capability as part of this cadence change."
  ],
  "validation": [
    {
      "check": "Focused offline observation suite",
      "status": "passed",
      "result": "All 77 observation, probation, scheduler, and dashboard tests passed in 3.80 seconds. Coverage includes source rotation, six-hour spacing, daily and finite caps, exact policy matching, deterministic probes, snapshot/projection hashes, proposal boundaries, and second-cycle execution."
    },
    {
      "check": "Complete Hiro suite",
      "status": "passed",
      "result": "All 397 tests passed in 114.98 seconds before the runtime policy was repinned."
    },
    {
      "check": "Clean pinned baseline",
      "status": "passed",
      "result": "The implementation was committed at e6c3672728668014faea1d288a92b08949d283f0 and Hiro's tracked working tree is clean. The runtime probation authorization now requires that exact SHA."
    },
    {
      "check": "Live service and dashboard API",
      "status": "passed",
      "result": "Hiro restarted through the checked-in normalized-environment launcher. Ports 8000, 8001, and 8765 are listening; the health page returns HTTP 200; and the observation API reports cycle 1 of 7, a six-hour interval, seven rotations, zero pending approvals, and Stage 6 disabled."
    },
    {
      "check": "Public journal generation and frontend build",
      "status": "passed",
      "result": "Timestamped-entry tests passed, all 76 journal pages and aliases validated, and the production frontend build completed successfully."
    }
  ],
  "currentState": [
    "The finite observation probation remains in progress at attempt 1 of 7; it has not passed or completed.",
    "The scheduler is currently blocked by the six-hour minimum interval and will make no request before 2026-08-06T13:47:39-07:00.",
    "Rotation 2 of 7 is next: Python source releases, PEP 0, and RFC Editor RFC 2606, with exactly one GET to each approved URL.",
    "There are zero pending observation case proposals and no newly approved evaluation case.",
    "The observation probation is armed under its finite authorization; Stage 6 DISABLED remains present and promotion authority remains false."
  ],
  "limitations": [
    "The new rotation code has passed offline tests but rotation two has not yet made a public request or produced real snapshot evidence.",
    "Official pages may change structure; a deterministic parser failure is recorded as an infrastructure failure and consumes an attempt rather than broadening authority or retrying indefinitely.",
    "Passing these bounded factual probes does not demonstrate open-ended web research, autonomous code promotion, or production safety.",
    "A baseline probe failure creates only a review proposal; it does not by itself establish that a code change is beneficial."
  ],
  "nextSteps": [
    "At or after 2026-08-06T13:47:39-07:00, allow the scheduler to run rotation two under the unchanged three-request safety budget.",
    "Verify the new session and snapshot SHA-256 companions, source URLs, response limits, probe outputs, evaluator tool use, and proposal count before classifying the cycle.",
    "Continue the remaining rotations at no less than six-hour intervals until attempt seven or any fail-closed condition restores the observation stop sentinel.",
    "Treat the finished seven-attempt record as evidence for a later observation-policy decision only; do not infer Stage 6 or promotion authorization."
  ],
  "disclosureNote": "This public entry contains no credentials, private held-out cases, raw retrieved page content, private network data, local filesystem paths, or actionable details about unresolved security weaknesses."
}
