rdmbair15m5-changelog-20260912-2128-tyrell-r3-containment-r4-preparation
rdmbair15m5 changelog — Tyrell r3 containment and r4 preparation
Contained an invalidated Build 20 r3 canary after the physical lid closed, restored exact signed Build 15/17, and prepared a corrected r4 harness that continuously enforces the host, AC-power, and open-clamshell envelope; this prevents a closed-lid interval from becoming a false acceptance.
Scope
- Changed host:
rdmbair15m5only. - No fleet host was expanded to Build 20.
- Canonical evidence was archived on
rdmsm4x; canonical Tyrell source and Git refs were not changed.
Exact files and state changed
- Stopped exact r3 guard PID
24726and its bound assertion helper PID24750after repeatedAppleClamshellState = Yesevidence. - Bounded rollback changed
/Applications/Tyrell.app,/Users/richh/Library/Application Support/Tyrell/bin/tyrelld, and/Users/richh/Library/LaunchAgents/com.eastcoastscience.tyrelld.plistback to the prepared exact prior artifacts. - R3 post-rollback state:
/Users/richh/.tyrell/build20-canary-r3-20260912-96a5fc0/state.json, SHA-256ca23a0887db84deeb62eb58573071ee9c53850073bd4bd2d240cf7c8b02ab77c. - Created prepared r4 stage
/Users/richh/.tyrell/build20-canary-r4-20260912-96a5fc0with a freshprior/snapshot and stagedcandidate/Tyrell.app. - R4 guard SHA-256:
2d4936f33d30472746e1496f976b2978a9c4974ce4e53d3e51a51ef2d3f6e2f9. - R4 launcher SHA-256:
dbae2acbf86293e555a3cfbdf14c40e809f5b1620dd30afaef5903c752c63d9e. - R4 prepared state SHA-256:
460922e735db9ca9f5e065994fc8c023d93c12f0d274f7c1d753c8952f50ade9.
Commands and operations
- Read AC/lid state, exact process identities, guard samples, inventory, launchd state, API health, SQLite integrity, and relevant power logs over SSH.
- Sent
SIGINT, then bounded wait, only to the exact r3 guard; verified no stage-matching guard process remained before rollback. - Ran the staged
canary_guard.py rollbackoperation once. - Built r4 from the pinned r3 release dependencies, adding in-loop power-envelope checks without changing the Build 20 product or memory policy.
- Ran Python compilation, zsh syntax checks, four deterministic
envelope tests, staged dependency preflight, fresh
prepare, and candidate signature/Gatekeeper/hash checks. - Did not install or launch Build 20 r4 because the lid remained physically closed.
Verification evidence
- R3 before containment remained product-healthy: 115 samples over
6840.774730seconds, maximum gap60.063863seconds, two unchanged inventory passes, final physical footprint62,457,008bytes, descriptors41, TCP descriptors2, and valid status/permission probes. - Rollback stable link resolves to
releases/daemon-dbc440bd54b8/tyrelld. - Installed daemon SHA-256 is exact Build 15:
dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0. - Installed app executable SHA-256 is exact Build 17:
8693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e. - Launchd reported PID
43219,runs=1, and never exited; both status planes returned HTTP 200 valid JSON; exactly one foreground app was running. - SQLite
quick_checkreturnedok, with one retained additivelast_seen_atcolumn and no database replacement. - Exact r4 candidate app hash
423871cede8ae6313c486929f544dbee8d1085540b2d37896de6f2c2d4de90fd, CDHash37a0081b06af970866e84877cc74524cdac750580d5fad22fb83d92d0eb0aa5c, strict signature, and notarized Gatekeeper assessment all passed. - Canonical receipts:
/Users/richh/dev/_handoff/tyrell-build20-memory-20260912/canary-r3-lid-closure/README.mdand/Users/richh/dev/_handoff/tyrell-build20-memory-20260912/canary-r4-prepared/R4-PREP.mdonrdmsm4x.
Backups and undo
- R4
prior/andprior.jsoncontain exact signed Build 15 daemon, Build 17 app, launchd plist, and the pinned pre-migration database-backup identity. - Pre-migration backup remains
/Users/richh/Library/Application Support/Tyrell/backups/20260912-0110-build20-preflight-96a5fc0/tyrell.db, SHA-256db29432be4fc962a18436f15f29d1677b10bc7c541d7f78eab6c00f7ecce3c8f; it was not restored because live additive data must be retained. - Current system state is already the rollback. If r4 is later launched and fails, its staged rollback operation restores the same exact Build 15/17 artifacts.
- The new r4 stage is additive and recoverable; do not delete r3/r4 evidence until acceptance and rollback coverage finish.
Outstanding actions
- Physical owner action: open the lid of
rdmbair15m5while it remains on AC power. - The monitor will independently verify that state before installing and launching exact Build 20 r4.
- Restart the short, six-hour-after-warmup, and fixed 24-hour clocks from zero; complete CPU, fresh-app, and reboot proofs before any fleet decision.
- Apple Notes entry on
rdmbair15m5is pending because this work was performed through a Background SSH session; the host-local changelog file is present and must be published from an Aqua GUI session withnotes_changelog.zsh.