{
  "schemaVersion": 2,
  "date": "2026.08.09",
  "publishedAt": "2026-08-09T12:35:35-07:00",
  "timeZone": "America/Los_Angeles",
  "title": "Stage 6B tightly bounded activation",
  "publicationStatus": "Activated and idle; one evidence-only promotion authorized through August 12",
  "executiveSummary": [
    "Following a separate explicit user approval, Hiro's Stage 6B evidence-only promotion lane was activated for one promotion during a 72-hour window ending August 12, 2026 at 12:30:53 Pacific time.",
    "The activation remains bound to revision 83902be5399cb4d90b95fb39422f2c9f126f1220, branch codex/rsi-first-cycle, repository identity, and policy SHA-256 5cd25cd44a86f3abb4400e8ca4dfce6a0ec6ea3cf0b6780c53efcd7fa9727c0f.",
    "A read-only enablement packet and sidecar were created, the persistent DISABLED sentinel was moved to a recoverable pre-activation backup, and a separate one-minute runner was registered with overlapping executions suppressed. The process environment opt-in exists only inside that runner.",
    "Repeated runner executions completed successfully in idle state. The candidate inbox is empty, the promotion ledger has zero events and zero outcomes, and no active-branch mutation occurred.",
    "Post-activation validation passed all 47 focused Stage 6 tests and all 414 repository tests. A pre-existing unrelated untracked directory keeps the repository from satisfying candidate clean-worktree preflight, so any candidate will continue to fail closed until that unrelated state is handled separately.",
    "Stage 6C remains undesigned and unauthorized; this activation cannot modify Hiro runtime code, existing files, services, external systems, or remote branches."
  ],
  "workstreams": [
    {
      "title": "User-bound activation authority",
      "status": "Completed",
      "details": [
        "Applied the separately approved first-enablement boundary without broadening it: evidence_only level, one promotion maximum, and a 72-hour validity window.",
        "Bound the packet to the exact repository, active branch, policy identity, policy hash, user approver role, and approving interaction.",
        "Wrote a companion SHA-256 sidecar and marked both packet files read-only. The production packet parser accepted their identity and immutability checks.",
        "The active policy's operation and content allowlists were not changed."
      ]
    },
    {
      "title": "Process-scoped opt-in and separate runner",
      "status": "Activated",
      "details": [
        "Created a host-local runner entry point in the ignored Stage 6 runtime directory so the reviewed Hiro revision remains unchanged.",
        "The runner loads the reviewed configuration and enables Stage 6B only in memory for that invocation; the tracked default remains false and ordinary Hiro startup remains unable to activate the lane.",
        "The launcher normalizes the Windows process search path from machine and user values before starting Hiro's pinned Python runtime, preserving the known dual-Path safety requirement.",
        "HIRO_STAGE6_AUTOPROMOTE=1 is set only in the runner child process. Verification showed the parent process environment remained unset."
      ]
    },
    {
      "title": "Bounded scheduling and kill-switch transition",
      "status": "Activated with recovery path",
      "details": [
        "Registered a separate Stage 6B task that invokes one tick per minute for the same 72-hour authorization duration.",
        "Configured overlapping executions to be ignored and bounded each invocation to a 30-minute execution limit.",
        "Moved the exact persistent DISABLED sentinel to a clearly named pre-activation backup only after the packet and launcher passed validation. Registration was transactional: a scheduler failure would have restored the sentinel.",
        "The first manual scheduled execution and subsequent automatic executions completed with result code zero and no missed runs."
      ]
    },
    {
      "title": "Post-activation validation",
      "status": "Passed",
      "details": [
        "A real child-process startup test initially failed safely because the host-local Python entry point lacked the Hiro module root. No sentinel or scheduling control had been changed at that point.",
        "Corrected the explicit module path and reran the child-process test successfully before opening the kill switch.",
        "After activation, reran all focused policy, shadow, transaction, production controller, and runner tests, then the complete repository suite.",
        "Verified repeated live ticks were idle, the inbox contained no candidate packet, and the append-only promotion ledger contained no promotion event or outcome."
      ]
    }
  ],
  "decisions": [
    "Keep the reviewed Git revision unchanged by placing activation-only launcher state in the ignored host runtime area rather than modifying tracked code or configuration after approval.",
    "Use a process-scoped environment opt-in rather than a machine-wide or user-wide variable, preserving ordinary startup as a non-authorizing path.",
    "Schedule one-minute ticks because required probation checkpoints allow at most five minutes of lateness; suppress overlapping task instances instead of permitting concurrent controllers.",
    "Preserve the former DISABLED sentinel as a recoverable backup rather than deleting it, while ensuring the exact live sentinel path is absent during the approved window.",
    "Do not move, delete, ignore, or otherwise conceal the unrelated untracked directory. Retain the controller's clean-worktree rejection until that state is resolved with separate authority.",
    "Do not create a candidate as part of activation. Candidate creation, frozen Stage 3-5 evidence, health baselines, and metrics baselines remain separate prerequisites.",
    "Do not grant any Stage 6C, runtime-fragment, existing-file, deployment, restart, external-action, or remote-push authority."
  ],
  "validation": [
    {
      "check": "Enablement packet parser",
      "status": "passed",
      "result": "The production parser accepted the read-only packet and sidecar as evidence_only, one promotion maximum, with the exact 72-hour validity window."
    },
    {
      "check": "Real launcher child process",
      "status": "passed after one safe correction",
      "result": "The first pre-activation launch exposed a missing module-root path and exited without changing activation controls. After the path correction, the child returned idle with candidate_inbox_scanned true and promotion_attempted false."
    },
    {
      "check": "Scheduled runner",
      "status": "passed",
      "result": "The bounded task registered successfully, suppresses overlapping instances, and repeated invocations returned result code zero with no missed runs."
    },
    {
      "check": "Focused Stage 6 suite after activation",
      "status": "passed",
      "result": "All 47 tests passed in 37.33 seconds."
    },
    {
      "check": "Full Hiro repository suite after activation",
      "status": "passed",
      "result": "All 414 tests passed in 127.44 seconds."
    },
    {
      "check": "Idle and mutation state",
      "status": "passed",
      "result": "The inbox contained zero JSON candidates, the ledger contained zero promotion events and zero outcomes, and the runner reported no promotion attempt."
    },
    {
      "check": "Independent controls",
      "status": "passed",
      "result": "The enablement files remained read-only, the exact live DISABLED path was absent, the recoverable sentinel backup existed, and the parent process environment opt-in remained absent."
    }
  ],
  "currentState": [
    "Stage 6B evidence-only authority is active from 2026-08-09T12:30:53-07:00 until 2026-08-12T12:30:53-07:00.",
    "The enablement permits at most one promotion and cannot be renewed or broadened by Hiro.",
    "The separate runner is healthy and currently idle.",
    "No candidate has been queued, evaluated, promoted, rolled back, or placed into probation.",
    "A pre-existing unrelated untracked directory currently prevents candidate clean-worktree authorization and preserves a fail-closed state.",
    "Stage 6C remains forbidden."
  ],
  "limitations": [
    "Activation alone does not create an eligible candidate or its immutable Stage 3-5 evidence packets.",
    "The active repository does not presently satisfy the clean-worktree precondition because of unrelated untracked content; this was deliberately left untouched.",
    "The scheduler is host-local and time-bounded. Its successful idle ticks do not demonstrate a production promotion or the full 24-hour probation sequence.",
    "A first candidate still requires compatible local health and metrics baselines and must pass targeted, Stage 6 policy, and full repository tests before any fast-forward.",
    "The controller cannot push a remote branch, modify existing files, restart services, or act externally."
  ],
  "nextSteps": [
    "Resolve or relocate the unrelated untracked repository content only with separate user direction, then reverify a fully clean active worktree.",
    "Allow Hiro's existing Stage 3-5 process to produce a single immutable eligible evidence-only candidate; do not manufacture or broaden a candidate during activation.",
    "When a candidate appears, verify its base revision, evidence packet identities, local health baseline, compatible metrics baseline, and add-only contents before the runner can start it.",
    "If the first candidate is promoted, monitor the immediate canary and all 0, 15, 60, 360, and 1,440-minute checkpoints through the complete 24-hour probation.",
    "At expiry or after the one-promotion cap is consumed, close the runner and restore the persistent DISABLED sentinel unless a new separate user decision explicitly authorizes another bounded window."
  ],
  "disclosureNote": "This public entry omits the user enablement packet contents, approving interaction details, private task principal, private filesystem paths, credentials, held-out cases, candidate content, and actionable unresolved security weaknesses."
}
