rdmbair15m5-changelog-20260913-1713-tyrell-build20-r5-ac-loss-rollback
Tyrell Build 20 R5 correctly failed closed when the designated canary lost AC power, preserving healthy product evidence and restoring the exact Build 15/17 rollback without touching the live database.
Tyrell Build 20 R5 AC-loss rollback
Date: 2026-09-13 17:06-17:13 EDT
Host changed: rdmbair15m5 only
Classification:
INCONCLUSIVE_ENVIRONMENTAL_INTERRUPTION_ROLLED_BACK
Why this matters
R5 had passed its short memory gate and remained healthy, but
uninterrupted open-lid/AC observation is mandatory. pmset
recorded the host switching to battery at 17:06:50 EDT. The continuously
enforced guard detected the power-envelope violation, stopped its
assertions, and restored the exact rollback. This is not evidence of a
Build 20 memory or service failure.
State changed
- R5 state changed from
soakingtorolled_backwith reasoncanary left AC power envelope. - Managed daemon symlink was restored to
/Users/richh/Library/Application Support/Tyrell/releases/daemon-dbc440bd54b8/tyrelld. /Applications/Tyrell.appwas restored to exact Build 17.- The replaced Build 20 app was retained as non-running rollback
evidence at
/Applications/.tyrell-rollbacks/20260913-170704-37a0081b06af/Tyrell.app. - Guard PID 24314 and assertion PID 24335 ended; both sleep assertions were released.
- R5 produced
failure-footprint.txt,failure-vmmap.txt,app-rollback.log, and finalstate.jsonartifacts. - No database restore, fleet expansion, deployment, or release action occurred.
Commands and verification
- Read
pmset -g batt,pmset -g log,ioreg, final state, artifacts, process inventory, assertions, hashes, launchd state, API responses, and live SQLite state over SSH. - Copied the final 60-sample JSONL, failure boundary, short-gate artifacts, logs, policy, validator, prior and migration records to canonical evidence storage.
- Re-verified exact daemon/app hashes, one app/bar process, launchd ownership, both status planes, and database integrity after automatic rollback.
Evidence
pmset:Using Batt(Charge: 100)at 17:06:50 EDT.- R5 state timestamp: 17:07:08 EDT;
daemon_healthy=true;app_rollback_rc=0. - 60 accepted Build 20 samples over 3541.266369 seconds; same PID/start/path; max gap 60.073440 seconds.
- All accepted samples were AC/open with zero invalid status or permission responses and no permission 503.
- Final accepted physical footprint: 60753168 bytes.
- Failure-boundary physical footprint: 60835088 bytes; sampled peak 524469760 bytes.
- Exact Build 15 daemon SHA-256:
dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0. - Rollback launchd: PID 79819, running, runs 1, never exited.
- Exact Build 17 app SHA-256:
8693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e. - Both ports 43117 and 43118: HTTP 200 valid JSON, correct host and role.
- Database:
PRAGMA quick_check=ok, exactly one additivefiles.last_seen_at, 153176 rows. - Canonical evidence:
/Users/richh/dev/_handoff/tyrell-build20-memory-20260912/canary-r5-ac-loss-20260913-1707/README.md - Canonical README SHA-256:
b6b4f3bafbc459056f8e045cd4284b979b34387a4f96e630e710dc6338f38b17
Backup, undo, and outstanding action
- Build 15 daemon and Build 17 app are already restored; no further undo is needed.
- Pre-migration backup remains
/Users/richh/Library/Application Support/Tyrell/backups/20260912-0110-build20-preflight-96a5fc0/tyrell.db, SHA-256db29432be4fc962a18436f15f29d1677b10bc7c541d7f78eab6c00f7ecce3c8f. Do not restore it over the healthy live additive database. - R5 short-gate pass remains historical, but its six-hour and 24-hour clocks are void.
- Owner action: reconnect
rdmbair15m5to AC and keep the lid open. - A fresh R6 stage must contain no copied R5 runtime evidence and may launch only after two fresh AC/open reads plus exact rollback, candidate, dependency, API, database, and no-writer preflights. Every clock restarts from zero.