Hiro development journal

End-to-end external idea lineage added to Hiro's Improvement Control Center

Implemented, validated, and active locally; Stage 6C readiness revalidated on the exact descendant revision Machine-readable JSON

Executive summary

Hiro's local Improvement Control Center now tracks a prompt-safe external idea from its reduced Moltbook or Reddit lead through specification, candidate construction, affected files, evaluation gates, Stage 5 integration, and Stage 6 approval or rejection.

A stable opaque lineage identifier is created from the external-source deduplication key. It carries through curiosity records, ImprovementSpecs, autonomous candidate requests, frozen candidate packets, and candidate-ledger events without revealing raw community text.

The first live view contains three Moltbook-derived safe idea records. Each honestly reports awaiting_local_corroboration because no locally supported specification or candidate has yet been created from those leads.

The tracking revision changed Hiro's exact Git identity, so the previously completed Stage 6C readiness state was checksum-verified, archived, and fully replayed against the new descendant revision. All readiness gates passed again and the Stage 6C runtime remains inactive.

Work completed

Durable prompt-safe idea identity

Implemented
  • Each accepted external lead receives a deterministic opaque identifier derived from its existing deduplication key rather than from displayed raw text.
  • The identifier format is strictly validated before it may enter an ImprovementSpec or candidate-build request.
  • Checksum-valid external-source packets are re-read through a dedicated lineage loader that enforces the source packet's non-propagation and no-authority declarations.
  • The loader exposes only the source name, bounded theme, locally testable safe question, hashed source reference, observation time, packet checksum, and corroboration requirement.
  • Raw external titles, post bodies, comments, and hostile instructions remain absent from lineage records and the dashboard API.

Candidate and evaluation joins

Implemented
  • Curiosity records and any later ImprovementSpec retain the origin lineage identifier and safe source metadata.
  • Autonomous candidate construction freezes the identifier into the checksum-bound candidate packet and its append-only ledger event.
  • The lineage API obtains actual affected files from the verified frozen candidate packet while retaining the separately declared allowed-path scope for comparison.
  • Public, held-out, regression, latency, and Stage 5 integration results are presented as named gates with pending, passed, or failed states.
  • Stage 6 outcomes are joined by the candidate's opportunity key, preserving the distinction between construction, rejection, queued eligibility, probation, retention, and rollback.

Operator-facing lineage view

Active on the local dashboard
  • A new Idea lineage tab presents the requested five-part path: original safe idea, constructed candidate, affected files, test gates, and approval or rejection status.
  • Records without local corroboration remain visibly incomplete instead of being represented as candidates.
  • The page distinguishes actual changed files from the candidate's declared scope and displays each gate independently for troubleshooting.
  • The endpoint and page are read-only. Viewing lineage grants no construction, integration, promotion, or Stage 6C authority.
  • Three current Moltbook records appeared after the first persisted live source cycle; all three are awaiting local corroboration and have zero linked candidates.

Exact-revision Stage 6C revalidation

Completed
  • A narrowly scoped revalidation operation was added for a completed default-off campaign whose target is an ancestor of a new clean revision.
  • The operation requires the completed campaign state, its frozen evidence checksum, unchanged policy checksum, clean descendant history, and the absence of all activation state.
  • The prior completed readiness record was archived with its own checksum before a new zero-progress campaign was created for the tracking revision.
  • The new campaign replayed every shadow-decision, reload, rollback, interruption, and full-repository gate rather than inheriting the prior ready status.
  • The resulting campaign is ready_for_activation on the exact tracking revision while runtime_fragment_active remains false.

Live restart and verification

Completed
  • The active loop was confirmed idle before restart, with no active Stage 6 promotion.
  • Hiro was restarted through the checked-in detached no-window launcher after its prior process tree was stopped and its expected ports closed.
  • The local dashboard returned HTTP 200, contained the Idea lineage tab, and returned three safe lineage records from the new API.
  • The post-restart pipeline retained its last completed external-source cycle and continued with no active Stage 6 promotion.
  • The detached process tree started cleanly and all local service listeners reported healthy startup.

Decisions and reasoning

Validation and evidence

CheckStatusResult
Focused lineage and campaign tests passed All 51 focused tests passed, covering source packet verification, safe reductions, lineage propagation, dashboard joins, candidate packets, cycle validation, autonomous construction, completed-campaign archival, and tampered-evidence rejection.
Full Hiro repository suite passed All 487 repository tests passed in 151.25 seconds before commit. The exact-revision Stage 6C runner then repeated the full repository gate successfully.
Stage 6C readiness replay passed The tracking revision passed 30 of 30 shadow decisions with zero false allows, 10 hot-reload rehearsals, three rollback drills, five interruption boundaries, and the required full-suite gate.
Local lineage API passed The live endpoint returned three lineages, zero linked candidates, three awaiting-corroboration states, and an explicit false value for raw external text exposure.
Local dashboard and service health passed The benchmark page returned HTTP 200 with the Idea lineage tab present, the active loop was idle rather than interrupted, and the hidden launcher reported a successful restart.

Current state

Next steps