Hiro development journal

Stage 6B tightly bounded activation

Activated and idle; one evidence-only promotion authorized through August 12 Machine-readable JSON

Executive summary

Following a separate explicit user approval, Hiro's Stage 6B evidence-only promotion lane was activated for one promotion during a 72-hour window ending August 12, 2026 at 12:30:53 Pacific time.

The activation remains bound to revision 83902be5399cb4d90b95fb39422f2c9f126f1220, branch codex/rsi-first-cycle, repository identity, and policy SHA-256 5cd25cd44a86f3abb4400e8ca4dfce6a0ec6ea3cf0b6780c53efcd7fa9727c0f.

A read-only enablement packet and sidecar were created, the persistent DISABLED sentinel was moved to a recoverable pre-activation backup, and a separate one-minute runner was registered with overlapping executions suppressed. The process environment opt-in exists only inside that runner.

Repeated runner executions completed successfully in idle state. The candidate inbox is empty, the promotion ledger has zero events and zero outcomes, and no active-branch mutation occurred.

Post-activation validation passed all 47 focused Stage 6 tests and all 414 repository tests. A pre-existing unrelated untracked directory keeps the repository from satisfying candidate clean-worktree preflight, so any candidate will continue to fail closed until that unrelated state is handled separately.

Stage 6C remains undesigned and unauthorized; this activation cannot modify Hiro runtime code, existing files, services, external systems, or remote branches.

Work completed

User-bound activation authority

Completed
  • Applied the separately approved first-enablement boundary without broadening it: evidence_only level, one promotion maximum, and a 72-hour validity window.
  • Bound the packet to the exact repository, active branch, policy identity, policy hash, user approver role, and approving interaction.
  • Wrote a companion SHA-256 sidecar and marked both packet files read-only. The production packet parser accepted their identity and immutability checks.
  • The active policy's operation and content allowlists were not changed.

Process-scoped opt-in and separate runner

Activated
  • Created a host-local runner entry point in the ignored Stage 6 runtime directory so the reviewed Hiro revision remains unchanged.
  • The runner loads the reviewed configuration and enables Stage 6B only in memory for that invocation; the tracked default remains false and ordinary Hiro startup remains unable to activate the lane.
  • The launcher normalizes the Windows process search path from machine and user values before starting Hiro's pinned Python runtime, preserving the known dual-Path safety requirement.
  • HIRO_STAGE6_AUTOPROMOTE=1 is set only in the runner child process. Verification showed the parent process environment remained unset.

Bounded scheduling and kill-switch transition

Activated with recovery path
  • Registered a separate Stage 6B task that invokes one tick per minute for the same 72-hour authorization duration.
  • Configured overlapping executions to be ignored and bounded each invocation to a 30-minute execution limit.
  • Moved the exact persistent DISABLED sentinel to a clearly named pre-activation backup only after the packet and launcher passed validation. Registration was transactional: a scheduler failure would have restored the sentinel.
  • The first manual scheduled execution and subsequent automatic executions completed with result code zero and no missed runs.

Post-activation validation

Passed
  • A real child-process startup test initially failed safely because the host-local Python entry point lacked the Hiro module root. No sentinel or scheduling control had been changed at that point.
  • Corrected the explicit module path and reran the child-process test successfully before opening the kill switch.
  • After activation, reran all focused policy, shadow, transaction, production controller, and runner tests, then the complete repository suite.
  • Verified repeated live ticks were idle, the inbox contained no candidate packet, and the append-only promotion ledger contained no promotion event or outcome.

Decisions and reasoning

Validation and evidence

CheckStatusResult
Enablement packet parser passed The production parser accepted the read-only packet and sidecar as evidence_only, one promotion maximum, with the exact 72-hour validity window.
Real launcher child process passed after one safe correction The first pre-activation launch exposed a missing module-root path and exited without changing activation controls. After the path correction, the child returned idle with candidate_inbox_scanned true and promotion_attempted false.
Scheduled runner passed The bounded task registered successfully, suppresses overlapping instances, and repeated invocations returned result code zero with no missed runs.
Focused Stage 6 suite after activation passed All 47 tests passed in 37.33 seconds.
Full Hiro repository suite after activation passed All 414 tests passed in 127.44 seconds.
Idle and mutation state passed The inbox contained zero JSON candidates, the ledger contained zero promotion events and zero outcomes, and the runner reported no promotion attempt.
Independent controls passed The enablement files remained read-only, the exact live DISABLED path was absent, the recoverable sentinel backup existed, and the parent process environment opt-in remained absent.

Current state

Next steps