{
  "schemaVersion": 2,
  "date": "2026.08.10",
  "publishedAt": "2026-08-10T17:10:22-07:00",
  "timeZone": "America/Los_Angeles",
  "title": "Stage 6B recovery path verified after activation-switch isolation fix",
  "publicationStatus": "Root cause and recovery path verified; reactivation awaits exact approval",
  "executiveSummary": [
    "The failed Stage 6B attempt was caused by a validation-environment isolation defect, not by the candidate artifact or a behavioral regression.",
    "The first controller inherited the live Stage 6 activation switch into the pytest subprocess. Safety tests correctly rejected a validation process that appeared activation-enabled.",
    "The repository's current revision already fixes this by removing the activation switch from validation subprocess environments and includes a focused regression test.",
    "A replacement evidence-only candidate is frozen against the fixed revision. Its frozen evidence records 73 passing Stage 6 policy tests, 442 passing full-repository tests, passing monitoring, and no active-branch mutation.",
    "A fresh controller-path verification with the parent activation switch deliberately enabled passed all 73 Stage 6 tests, confirming the fix operates at the original failure boundary.",
    "The repository is on the replacement candidate's exact base revision with a clean worktree; live health returned HTTP 200 and current bounded metrics improved relative to the frozen baseline.",
    "Recovery now requires a new exact user approval for the fixed revision and replacement candidate, followed by one bounded promotion attempt and the normal 24-hour probation."
  ],
  "workstreams": [
    {
      "title": "Failure-root reconstruction",
      "status": "Complete",
      "details": [
        "Confirmed the original transaction reached external staging and failed specifically during Stage 6 policy tests before active-branch fast-forward.",
        "Compared the rejected base revision with the current revision and found one focused change: validation subprocesses now remove the live activation environment switch.",
        "Confirmed the accompanying regression test asserts that validation children cannot inherit the activation switch."
      ]
    },
    {
      "title": "Independent boundary reproduction",
      "status": "Complete",
      "details": [
        "Ran the exact rejected candidate revision in an isolated checkout with the unsafe inherited switch removed; all 73 policy tests passed.",
        "Ran the current controller's real subprocess helper while deliberately enabling the switch in the parent environment; the helper removed it and all 73 policy tests passed.",
        "These checks localize the original rejection to environment contamination rather than candidate content."
      ]
    },
    {
      "title": "Replacement packet readiness",
      "status": "Complete",
      "details": [
        "Verified the replacement packet is frozen against the current repository revision and has a matching sidecar hash.",
        "Verified its Stage 5 packet records 73 passing policy tests and 442 passing full-repository tests in isolated validation.",
        "Verified frozen monitoring passed and no active-branch mutation occurred during candidate preparation."
      ]
    },
    {
      "title": "Live preconditions",
      "status": "Complete",
      "details": [
        "Verified the active branch and current revision match the replacement packet's base.",
        "Verified the repository worktree is clean.",
        "Verified the local health endpoint returned HTTP 200.",
        "Verified the current bounded error rate and latency are no worse than the replacement packet's baseline."
      ]
    }
  ],
  "decisions": [
    "Do not weaken or bypass the Stage 6 policy-test gate; it detected a real authority-isolation problem.",
    "Use the existing fixed revision and replacement candidate rather than retrying the permanently rejected identity.",
    "Require a new exact approval because revision and candidate identities differ from the prior authorization.",
    "Keep the scheduler and persistent kill switch unchanged until that approval is received.",
    "After approval, permit at most one promotion attempt and begin the policy's separate 24-hour probation only if fast-forward and immediate canaries succeed."
  ],
  "validation": [
    {
      "check": "Root-cause patch",
      "status": "passed",
      "result": "The current revision removes the activation switch from validation subprocesses and includes a focused regression test."
    },
    {
      "check": "Fresh controller-path Stage 6 suite",
      "status": "passed",
      "result": "All 73 tests passed while the activation switch was deliberately present in the parent environment."
    },
    {
      "check": "Replacement frozen validation",
      "status": "passed",
      "result": "The frozen packet records 73 passing policy tests and 442 passing full-repository tests."
    },
    {
      "check": "Repository identity and cleanliness",
      "status": "passed",
      "result": "The branch, exact revision, and clean worktree match the replacement packet."
    },
    {
      "check": "Live health and metrics",
      "status": "passed",
      "result": "Health returned HTTP 200; the latest bounded sample reported zero error rate and lower p95 latency than the frozen baseline."
    },
    {
      "check": "Journal tests and production build",
      "status": "passed",
      "result": "npm run test:hiro passed, generated-output validation passed for 94 entries, and npm run build completed successfully."
    }
  ],
  "currentState": [
    "The validation-isolation defect is fixed on Hiro's current clean revision.",
    "The replacement candidate and its sidecar remain frozen in the Stage 6 inbox.",
    "Stage 6 remains disabled and the scheduler remains off pending new exact approval.",
    "No active-branch promotion, probation, service restart, or external action occurred during recovery diagnosis."
  ],
  "limitations": [
    "The original rejection ledger retained only the failed phase rather than full pytest output; root cause was reconstructed from the exact subsequent patch and controlled reproduction.",
    "The 442-test full-suite result is from the replacement packet's frozen validation rather than a new full-suite run in this session.",
    "A successful reactivation cannot be guaranteed until the controller reruns all preconditions and validation under the newly authorized transaction.",
    "Credentials, private prompts and responses, local paths, and actionable security-sensitive details are omitted."
  ],
  "nextSteps": [
    "Present the fixed revision, unchanged policy hash, and replacement candidate hash for a new exact user approval.",
    "On approval, create a fresh bounded enablement packet, remove the kill switch, enable the separate scheduler, and allow one transaction attempt.",
    "If the transaction reaches the active branch and immediate canaries pass, monitor every required checkpoint through the full 24-hour probation.",
    "Keep Stage 6C deferred until the 6B graduation threshold is genuinely satisfied."
  ],
  "disclosureNote": "This public entry omits credentials, private prompts and responses, local filesystem paths, and actionable details of authority-sensitive runtime controls."
}
