{
  "schemaVersion": 2,
  "date": "2026.08.09",
  "publishedAt": "2026-08-09T15:37:26-07:00",
  "timeZone": "America/Los_Angeles",
  "title": "Stage 6 activation fails closed, then produces a corrected replacement",
  "publicationStatus": "Replacement candidate ready; Stage 6 disabled",
  "executiveSummary": [
    "The user approved one tightly bounded Stage 6B activation for the previously reviewed revision, policy, and candidate identities.",
    "The controller accepted the exact authorization and passed preflight, but rejected the candidate before any active-branch mutation when its required live activation environment value leaked into the validation subprocess and caused nine forced-shadow tests to fail.",
    "The failure was contained as designed: no fast-forward occurred, no promotion entered probation, the scheduled task was disabled, and the persistent Stage 6 kill switch was restored.",
    "The subprocess boundary now removes the live activation variable from child validation commands. A focused regression test, the complete Stage 6 policy suite, and the complete repository suite passed on the corrected revision.",
    "A replacement candidate with a new fail-closed identity was rebuilt from the same real Daylab run. Base and isolated validation passed, live monitoring remained unchanged, and the new packet was frozen.",
    "Stage 6 remains disabled. The user can shut Hiro down for several hours without losing the frozen packet, and a fresh 72-hour window will begin only after restart and a new exact approval."
  ],
  "workstreams": [
    {
      "title": "Exact activation attempt",
      "status": "Rejected before promotion",
      "details": [
        "Verified the approved Git revision, active policy hash, candidate packet hash, immutable review packet, repository identity, and active branch before changing runtime controls.",
        "Archived the superseded enablement, froze a new 72-hour one-promotion enablement packet, removed the external sentinel, enabled the scheduled task, and started one immediate tick.",
        "The append-only ledger recorded lease acquisition, successful preflight, and isolated candidate staging before recording a validation rejection.",
        "No fast-forward event exists and the active Hiro revision did not change during the attempt."
      ]
    },
    {
      "title": "Failure diagnosis and containment",
      "status": "Contained",
      "details": [
        "The first scheduled launch returned a nonzero result before writing a promotion outcome. A direct diagnostic tick confirmed that the ledger refused to reuse the incomplete pre-fast-forward candidate identity.",
        "Ledger inspection identified the failed phase as the Stage 6 policy suite.",
        "Reproduction with the live opt-in environment value produced nine deterministic failures in forced-shadow transaction tests; the same suite passed without that inherited value.",
        "The scheduler was disabled, the sentinel was restored, and the rejected packet and its companion hash were preserved outside the live inbox."
      ]
    },
    {
      "title": "Validation-environment isolation",
      "status": "Implemented",
      "details": [
        "Child validation commands now remove every case-insensitive instance of the live Stage 6 activation variable while retaining the normalized Windows process environment and pinned runtime.",
        "Added a regression test that runs a real child interpreter and asserts the activation value is absent.",
        "Committed the correction as revision cafd1d585bed86f233f0201bb26a23a0f1e0ab0d."
      ]
    },
    {
      "title": "Replacement evidence candidate",
      "status": "Frozen and waiting",
      "details": [
        "Rebuilt the same documentation-only evidence artifact from the original completed Daylab summary under a new opportunity, candidate, and promotion identity, as required by the append-only ledger after a pre-fast-forward rejection.",
        "The replacement remains one additive Markdown file, makes no runtime behavior change, and binds the same source run summary hash.",
        "The packet and its sidecar agree on SHA-256 bb6ffd4cc89ada554e5ad1b5212bfffebe1684203aeff1f0c991f84ef09880ea.",
        "A new immutable activation-review packet records the rejected attempt, corrected revision, replacement identity, validation evidence, disabled scheduler, and restored sentinel."
      ]
    }
  ],
  "decisions": [
    "Treat a validation failure as consuming the candidate identity even though no active-branch mutation occurred; do not erase or rewrite append-only ledger history.",
    "Do not silently substitute a replacement packet for the candidate hash the user explicitly approved.",
    "Strip activation authority from validation subprocesses because tests must execute in a neutral environment while the parent controller retains the exact live opt-in.",
    "Restore all external shutdown controls before engineering or rebuilding a replacement candidate.",
    "Delay the next authorization window until Hiro is restarted so planned downtime does not consume the useful 72-hour observation period."
  ],
  "validation": [
    {
      "check": "Failure reproduction",
      "status": "confirmed",
      "result": "With the live activation value inherited, the policy suite produced 9 failures and 63 passes; without it, all 72 tests on the original revision passed."
    },
    {
      "check": "Environment-isolation regression",
      "status": "passed",
      "result": "The focused child-process regression passed and verified that validation cannot inherit the live activation switch."
    },
    {
      "check": "Corrected integrated Stage 6 suite",
      "status": "passed",
      "result": "73 policy-defined Stage 6 tests passed in 42.15 seconds."
    },
    {
      "check": "Corrected integrated full suite",
      "status": "passed",
      "result": "442 repository tests passed in 129.43 seconds."
    },
    {
      "check": "Replacement base validation",
      "status": "passed",
      "result": "The replacement pipeline passed 73 Stage 6 tests in 42.23 seconds and all 442 repository tests in 127.66 seconds on the clean base."
    },
    {
      "check": "Replacement isolated validation",
      "status": "passed",
      "result": "The detached candidate worktree passed 73 Stage 6 tests in 42.27 seconds and all 442 repository tests in 130.53 seconds."
    },
    {
      "check": "Replacement monitoring",
      "status": "passed",
      "result": "Both monitoring snapshots contained 100 observations, error rate 0.04, and p95 latency 10,022 ms, with no measured increase."
    },
    {
      "check": "Replacement packet integrity",
      "status": "passed",
      "result": "The candidate packet hash matches its sidecar; the new activation-review packet is also hash-bound and read-only."
    }
  ],
  "currentState": [
    "The active Hiro revision is cafd1d585bed86f233f0201bb26a23a0f1e0ab0d and the Git worktree is clean.",
    "The active Stage 6 policy hash remains 09704eca80e2160f4305b01997deb8ab958146deadca6b1a7352ec59e770be08.",
    "The rejected original candidate was never fast-forwarded and is preserved outside the inbox with immutable ledger evidence.",
    "Exactly one replacement candidate waits in the inbox with packet hash bb6ffd4cc89ada554e5ad1b5212bfffebe1684203aeff1f0c991f84ef09880ea.",
    "The Stage 6 scheduled task is disabled, the persistent sentinel is present, and there are no active promotions or probation records.",
    "The replacement activation-review packet hash is b072d87cc3873d01d2dfb62bc71d007bc0a166df8494117a8f771cf54e89f7ee.",
    "Hiro may now be taken offline without affecting the frozen evidence packet."
  ],
  "limitations": [
    "The replacement candidate is not covered by the earlier exact approval because both the revision and candidate packet hash changed.",
    "The replacement remains a documentation-evidence promotion and does not fix the evaluation failures captured by the source run.",
    "No new promotion attempt can occur while Hiro is offline or while the scheduler and sentinel remain disabled.",
    "The scheduled launcher does not yet persist a complete Python traceback when PowerShell treats native stderr as a terminating error; direct diagnosis supplied the evidence for this incident."
  ],
  "nextSteps": [
    "Allow Hiro to remain offline for the user's planned maintenance period; retain the disabled scheduler and sentinel.",
    "After Hiro restarts, verify local health and Stage 6 metrics before changing authorization controls.",
    "Obtain explicit approval bound to corrected revision cafd1d585bed86f233f0201bb26a23a0f1e0ab0d, the unchanged policy hash, replacement packet hash bb6ffd4cc89ada554e5ad1b5212bfffebe1684203aeff1f0c991f84ef09880ea, one promotion, and a fresh 72-hour window.",
    "On approval, create a new immutable enablement packet and observe the replacement through preflight, fast-forward, immediate canary, and timed probation checkpoints.",
    "Improve launcher failure capture without weakening fail-closed transaction behavior."
  ],
  "disclosureNote": "This public entry omits private prompts and responses, credentials, local filesystem paths, model configuration details, and actionable unresolved security information."
}
