Hiro development journal

Stage 6B evidence-only promotion preparation

Implementation complete; awaiting separate activation approval Machine-readable JSON

Executive summary

Hiro's Stage 6B evidence-only automatic-promotion implementation is complete on revision 83902be5399cb4d90b95fb39422f2c9f126f1220, but it remains operationally disabled.

A new fail-closed production controller validates the exact active policy, immutable user enablement, frozen candidate and Stage 3-5 evidence identities, repository state, rate limits, kill switches, and the add-only v1 content boundary before any active-branch change.

Eligible candidates are reproduced in an external worktree, validated with targeted, Stage 6 policy, and full repository tests, and integrated only by a single fast-forward directly above the exact base. The controller contains no remote-push operation.

Immediate and probation canaries combine deterministic tests, local health status, and compatible error-rate and p95-latency observations. Required checkpoints occur at 0, 15, 60, 360, and 1,440 minutes, with late or failed checkpoints triggering additive Git-revert rollback.

A separate single-tick runner is compiled default-off. While disabled it returns before opening the promotion ledger or scanning the candidate inbox; when separately enabled, it resumes active probation before considering new work and refuses a non-singular inbox.

All 47 focused Stage 6 tests and all 414 Hiro repository tests passed. A frozen activation-review packet binds the final revision and policy hash, but no user enablement packet was issued and no activation control was changed.

Work completed

Final evidence-only policy

Completed and awaiting hash approval
  • Added the final schema-version-1 policy for the evidence_only level while retaining the disabled draft as immutable shadow-campaign context.
  • The policy permits at most two new UTF-8 non-executable evidence files, 16 KiB and 120 added lines total, and only documentation evidence, passing regression captures, or quarantined benchmark candidates.
  • Existing-file modification, deletion, rename, mode change, symlink, submodule, runtime code, evaluator changes, service control, restarts, external actions, and Stage 6C authority remain forbidden.
  • The final policy SHA-256 is 5cd25cd44a86f3abb4400e8ca4dfce6a0ec6ea3cf0b6780c53efcd7fa9727c0f.

Production transaction controller

Completed behind inactive controls
  • Implemented a distinct production controller rather than weakening the forced-shadow fixture adapter.
  • Authorization requires the compiled feature opt-in, exact environment key and value without a case-variant duplicate, absent external DISABLED sentinel, active policy hash match, read-only user packet and sidecar, repository and branch binding, valid time window, and no open emergency stop.
  • Candidate preflight reuses the benchmarked classifier and independently verifies read-only packet hashes, five required Stage 3-5 evidence packet kinds, exact base, clean worktree, no Git operation, rate limits, cooldowns, and one active lease.
  • The controller creates an external candidate worktree and a single-parent candidate commit, reruns targeted and policy tests plus the entire repository suite, creates a pre-promotion reference, rechecks authority and repository identity, and then permits only fast-forward integration.
  • Every state transition and terminal outcome is append-only and identity-bound. Reusing a promotion ID with changed evidence fails closed.

Canary, probation, and recovery

Completed
  • Immediate validation reruns the Stage 6 policy suite and full repository suite, then runs candidate canaries, local health checks, and compatible metrics checks.
  • Metrics enforcement requires at least 40 compatible observations and applies the frozen error-rate and p95-latency thresholds from the policy.
  • Probation is resumable and admits only the next scheduled checkpoint. A checkpoint over five minutes late is treated as missed and rolls back.
  • Rollback requires the exact promoted HEAD, creates an additive Git revert, verifies the baseline-equivalent tree, reruns policy and full tests plus health checks, and activates the persistent disabled sentinel.
  • Overlapping active-branch state, rollback uncertainty, corrupted audit state, or unavailable post-promotion candidate identity produces an emergency stop without an unsafe revert attempt.

Separate default-off runner

Completed and disabled
  • Added a single-tick adapter separate from nightly evaluation and candidate construction.
  • With the feature flag false, the runner returns disabled before opening the ledger or looking at the inbox.
  • When separately authorized, one active probation is checked before new candidates are considered; more than one active probation activates the persistent emergency stop.
  • With no active probation, an empty inbox is idle and an inbox containing more than one candidate is rejected without selecting one.

Activation-review evidence

Frozen; no activation performed
  • Committed the controller and policy in revision 53ba99c300098cf321265bacd1de43c1de236b57, then added the separate default-off runner and finalized revision 83902be5399cb4d90b95fb39422f2c9f126f1220.
  • Preserved the first review packet after the final runner changed the revision and policy hash, then issued a clearly superseding read-only packet rather than rewriting frozen evidence.
  • The superseding review packet SHA-256 is 8b1c3ea9209ce09fead0885eb42ada4494353f7be3944bfeef167a769b62366f.
  • The proposed first enablement remains conservative: one evidence-only promotion in a 72-hour window, subject to separate explicit user approval.

Decisions and reasoning

Validation and evidence

CheckStatusResult
Focused Stage 6 suite passed All 47 policy, shadow classification, fixture transaction, production promotion, metrics, rollback, emergency-stop, audit, and runner tests passed in 44.70 seconds.
Full Hiro repository suite passed All 414 tests passed in 153.16 seconds on the exact working content committed as revision 83902be5399cb4d90b95fb39422f2c9f126f1220.
Production controller safety paths passed Tests covered default-off authorization, both kill switches, duplicate environment keys, tampered packets, add-only fast-forward, one active probation, all real-time checkpoints, failed and missed-checkpoint rollback, overlapping state, candidate loss, metrics regression, and append-only audit enforcement.
Default-off runner probe passed The real runner returned status disabled, reported that the candidate inbox was not scanned, and performed no promotion attempt.
Repository diff validation passed Git diff whitespace validation passed before each implementation commit.
Final activation-review packet passed The superseding packet and sidecar are read-only and the packet SHA-256 verified as 8b1c3ea9209ce09fead0885eb42ada4494353f7be3944bfeef167a769b62366f.
Activation controls after implementation passed The compiled feature default is false, the runner is default-off, the activation environment value is absent, the persistent DISABLED sentinel is present, and no user enablement packet exists.

Current state

Next steps