rdmbair15m5-changelog-20260913-1612-tyrell-build20-r5-canary-launch
Exact signed/notarized Tyrell Build 20 was promoted on the designated
rdmbair15m5 canary and launched under the continuous
open-lid/AC rollback guard; the canary is soaking, not accepted or
expanded fleet-wide.
Tyrell Build 20 R5 canary launch
Date: 2026-09-13 16:04-16:12 EDT
Host changed: rdmbair15m5 only
Project: Tyrell
State: SOAKING_NOT_ACCEPTED
Why this matters
The original tyrelld outage was caused by launchd
referencing a mutable build-tree executable that disappeared. Build 20
carries the durable hash-addressed service lifecycle fix plus the
allocator remediation developed after Build 19 failed its six-hour
memory gate. R5 restarts the designated physical canary after R4
correctly failed closed when the laptop lid was closed.
Changes made
- Promoted the pinned Build 20 app to
/Applications/Tyrell.appwithscripts/install_app_local.zsh. - Retained the replaced exact Build 17 app at
/Applications/.tyrell-rollbacks/20260913-160416-2c5ca2a674fe/Tyrell.app. - Launched
/Users/richh/.tyrell/build20-canary-r5-20260913-96a5fc0/launch_guard_power_protected.zsh. - The guard promoted the pinned Build 20 daemon into
/Users/richh/Library/Application Support/Tyrell/releases/daemon-71bf6122e453/tyrelld, repointed the managed stable symlink, rendered the LaunchAgent, and bootstrappedcom.eastcoastscience.tyrelld. - The guard continuously verifies exact host, AC power, open
clamshell, candidate identity, daemon process identity, endpoints,
sampling continuity, and timed memory policy. It runs under both
PreventSystemSleepandPreventUserIdleSystemSleepassertions. - No database restore, fleet expansion, public release, or remote publication was performed.
Exact files and state touched
/Applications/Tyrell.app/Applications/.tyrell-rollbacks/20260913-160416-2c5ca2a674fe/Tyrell.app/Users/richh/Library/Application Support/Tyrell/bin/tyrelld/Users/richh/Library/Application Support/Tyrell/releases/daemon-71bf6122e453/tyrelld/Users/richh/Library/LaunchAgents/com.eastcoastscience.tyrelld.plist- R5 runtime outputs under
/Users/richh/.tyrell/build20-canary-r5-20260913-96a5fc0/:app-install.log,daemon-install.log,guard.log,guard.pid,inventory.log,latest.json,migration.json,samples.jsonl,startup-footprint.txt,startup-vmmap.txt, andstate.json.
Commands run
- Repeated read-only host, AC/open-clamshell, process, hash, code-signature, endpoint, and database preflights over SSH.
sudo -n zsh .../scripts/install_app_local.zsh --bundle .../candidate/Tyrell.app --expected-hash 423871cede8ae6313c486929f544dbee8d1085540b2d37896de6f2c2d4de90fd --expected-cdhash 37a0081b06af970866e84877cc74524cdac750580d5fad22fb83d92d0eb0aa5c --target-user richhnohup .../launch_guard_power_protected.zsh.../verify_guard_power_protected.zsh- Independent
launchctl print,ps,pgrep,pmset,ioreg,codesign,shasum,curl,jq, andsqlite3verification.
Verification evidence
- App executable SHA-256:
423871cede8ae6313c486929f544dbee8d1085540b2d37896de6f2c2d4de90fd - App arm64 CandidateCDHashFull SHA-256:
37a0081b06af970866e84877cc74524cdac750580d5fad22fb83d92d0eb0aa5c - Daemon SHA-256:
71bf6122e453315205f3f0dfaf3f1a3a6cf2d99dfe901cda88e7ac79a8112c77 - At 16:07:57 EDT: app PID 21840, TyrellBar PID 21944, daemon PID 24460, guard PID 24314, assertion PID 24335.
- launchd: running, runs 1, PID 24460, never exited.
- Both 43117 and 43118: HTTP 200 with valid JSON, host
rdmbair15m5, roleclient. - Database:
PRAGMA quick_check=ok, 153160 rows, exactly one additivefiles.last_seen_atcolumn. - Power: AC;
AppleClamshellState=No. - Assertions:
PreventSystemSleep=1andPreventUserIdleSystemSleep=1, bound to the exact guard lifetime. - Three same-PID/start/path launch samples span 120.724573 seconds. Physical footprint moved from 260670760 bytes to 430835200 bytes. This is above the later 300 MiB ceiling but precedes the ten-minute warmup and 40-minute verdict, so it is an observation rather than a gate result.
- Canonical receipt:
/Users/richh/dev/_handoff/tyrell-build20-memory-20260912/canary-r5-launch-20260913-1606/README.md - Canonical receipt SHA-256:
9b68a128af510e28d33d83c917816ac8cc0d0325b6b9df29a96d5cea021400be
Backups and rollback
- App rollback SHA-256:
8693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e - Daemon rollback:
/Users/richh/Library/Application Support/Tyrell/releases/daemon-dbc440bd54b8/tyrelld - Daemon rollback SHA-256:
dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0 - Pre-migration database backup:
/Users/richh/Library/Application Support/Tyrell/backups/20260912-0110-build20-preflight-96a5fc0/tyrell.db - Backup SHA-256:
db29432be4fc962a18436f15f29d1677b10bc7c541d7f78eab6c00f7ecce3c8f - Undo: allow the exact R5 fail-closed guard to invoke its bounded
rollback; do not manually restore the database over the live additive
schema. Independently verify the retained Build 15/17 hashes, launchd
state, both endpoints, one app/bar process, and
PRAGMA quick_checkafterward.
Outstanding gates
- Short gate: 2026-09-13 16:46:58 EDT.
- Six-hour-after-warmup gate: 2026-09-13 22:16:58 EDT.
- Fixed 24-hour endpoint: 2026-09-14 16:06:58 EDT.
- Repeated inventory, CPU, fresh-app, reboot, fleet rollout, and release gates remain open.
- If host, AC, open-clamshell, process identity, endpoint, sample-continuity, or memory policy fails, R5 must fail closed and preserve the failure/rollback evidence.