rdmbair15m5-changelog-20260913-1740-tyrell-build20-r6-canary-launch
Tyrell Build 20 R6 was launched under the fail-closed power-protected guard on the designated canary after AC returned and two full power/preflight boundaries passed; all acceptance clocks restarted from zero.
Tyrell Build 20 R6 canary launch
Date: 2026-09-13 17:34-17:40 EDT
Host changed: rdmbair15m5 only
State: SOAKING_NOT_ACCEPTED
Changes
- Promoted the exact signed/notarized Build 20 app to
/Applications/Tyrell.app. - Retained exact Build 17 at
/Applications/.tyrell-rollbacks/20260913-173611-2c5ca2a674fe/Tyrell.app. - Launched
/Users/richh/.tyrell/build20-canary-r6-20260913-96a5fc0/launch_guard_power_protected.zsh. - The guard promoted exact Build 20 daemon into its retained
hash-addressed release, repointed the managed stable link, and
bootstrapped
com.eastcoastscience.tyrelld. - Created R6 runtime state, migration, inventory, memory, guard, and installer logs within the isolated R6 stage.
- No database restore, fleet expansion, deployment, or release occurred.
Preflight and commands
- Two fresh power reads at 17:34:50 and 17:35:49 EDT independently reported AC power and open clamshell.
- Verified exact R6 state/prior hashes, no-runtime allowlist, every candidate/harness/dependency hash, strict signatures, Gatekeeper, arm64 full code-directory hash, universal daemon architectures, exact Build 15/17 rollback processes, both API planes, live and backup database integrity, and no competing writer.
- Ran the pinned app installer first with
--dry-run, then the actual promotion with exact expected app hash/CDHash. - Re-read AC/open, app identity, unchanged daemon rollback, APIs, and database before launching only the pinned R6 wrapper.
- Ran the exact guard verifier plus independent process, assertion, launchd, code identity, API, SQLite, sample, and rollback checks.
Verification
- App SHA-256:
423871cede8ae6313c486929f544dbee8d1085540b2d37896de6f2c2d4de90fd; PID 6348. - App arm64 CandidateCDHashFull:
37a0081b06af970866e84877cc74524cdac750580d5fad22fb83d92d0eb0aa5c. - TyrellBar PID 6481; exactly one app and one bar.
- Daemon SHA-256:
71bf6122e453315205f3f0dfaf3f1a3a6cf2d99dfe901cda88e7ac79a8112c77; PID 7363; process start 17:36:42 EDT. - launchd: running, runs 1, never exited.
- Guard PID 7237; child assertion PID 7258; both
PreventSystemSleepandPreventUserIdleSystemSleepbound to guard lifetime. - Both status ports: HTTP 200 valid JSON, correct host/role.
- Live database:
quick_check=ok, one additivelast_seen_at, 153184 rows. - Two initial samples: same PID/start/path, 60.031763-second gap, AC/open, valid status and permission probes, TCP 2.
- Initial physical footprint 255001896 bytes; at 60.676 seconds 412780032 bytes. This pre-warmup value is retained diagnostically and is not a gate verdict.
- Exact Build 15/17 rollback and database backup remain available.
- Canonical receipt:
/Users/richh/dev/_handoff/tyrell-build20-memory-20260912/canary-r6-launch-20260913-1736/README.md - Receipt SHA-256:
a9d8299f26d81d7af2a85dee94f5271194407939fb8afaaf6af56fe7b2742dcb
Rollback and outstanding gates
- Build 17 rollback SHA-256:
8693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e. - Build 15 daemon rollback SHA-256:
dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0. - Database backup SHA-256:
db29432be4fc962a18436f15f29d1677b10bc7c541d7f78eab6c00f7ecce3c8f; never restore over the healthy live additive database. - On any invariant failure, allow the exact guard to perform bounded rollback and independently verify it.
- Warmup ends 17:46:43 EDT; short gate 18:16:43; six-hour-after-warmup 23:46:43; fixed 24-hour gate September 14 at 17:36:43.
- Repeated inventory, CPU, fresh app, reboot, fleet, deployment, and release gates remain pending.