rdmbair15m5 changelog — Tyrell Build 20 R6 failed rollback and R7 guard hardening
Build 20 R6 encountered a closed-lid environmental boundary and exposed a missing rollback-payload bug; exact Build 15/17 service was restored, the defect was filed as ISSUE-20260913-09, and a tested fail-before-mutation R7 harness is prepared but not launched.
Scope
- Runtime host changed:
rdmbair15m5only. - Coordinator host:
rdmpw3275m. - Canonical ticket store:
rdmsm4x:/Users/richh/dev/issues. - No fleet expansion, source merge, release tag, database restore, or production acceptance.
Files and state changed
- Reconstructed
/Users/richh/.tyrell/build20-canary-r6-20260913-96a5fc0/prior/from the retained hash-matched R5 rollback snapshot so the interrupted rollback could finish. - R6
state.jsonnow recordsrolled_backwith healthy daemon and app rollback return code 0. - Restored
/Users/richh/Library/Application Support/Tyrell/bin/tyrelldto exact Build 15 release SHAdbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0. - Restored
/Applications/Tyrell.appto exact Build 17 executable/bundle hash8693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e. - Created prepared inert R7 stage
/Users/richh/.tyrell/build20-canary-r7-20260913-96a5fc0with a complete verifiedprior/payload. - Retained disposable rollback self-test stage
/Users/richh/.tyrell/build20-canary-r7-rollback-selftest-20260913. - Retained failed implementation iteration
/Users/richh/.tyrell/build20-canary-r7-prepare-failed-20260913-1823-plist-parserfor provenance. - Authored hardened guard SHA
f1e5e55fd1aaf9d58a9dfe8a9a3df87e7dd35e351f5ff35d2e5717ab4fe6ad3dand launcher SHA2ecc1632e5f6ab70ba3bc763c2b3bf10a533a9d0c8f79dd39613d0acaad26448. - Filed canonical
ISSUE-20260913-09and related it toISSUE-20260912-14,ISSUE-20260905-23, andTASK-20260911-01.
Commands and operations
- Inspected R6 state, samples, power envelope, guard traceback, stable link, launchd state, signatures, hashes, app processes, APIs, and database integrity over SSH.
- Compared R6 rollback metadata against the retained R5 daemon, plist, and app snapshot before copying it.
- Re-ran the bounded guard rollback only after exact hash and bundle verification.
- Implemented guard v1.3 and launcher v1.3 in the coordinator handoff workspace, then copied the exact files into a fresh R7 stage.
- Ran Python compilation, zsh syntax checks, pinned dependency verification, R7 preparation, positive payload validation, missing-payload negative validation, direct negative rollback injection, and a full disposable rollback transaction.
- Rechecked launchd identity, both authenticated local API planes without persisting token data, app/bar process counts, stable artifact hashes, and SQLite quick-check.
Verification evidence
- R6 failure time: 2026-09-13 18:13:45 EDT; root exception was missing
prior/daemon.plistafter bootout. - R6 product observations before interruption: 37 same-PID/start/path samples, 2,161.018400 seconds, max gap 60.044062 seconds, zero status/permission failures or 503s, last physical 33,457,424 bytes.
- Manual containment ended in
rolled_back; no Build 20 daemon or R6 guard remained. - Hardened negative rollback test failed before mutation with baseline PID/start/SHA unchanged.
- Hardened full rollback self-test changed baseline daemon PID 44533
to 52647, then both
/api/statusplanes returned HTTP 200 and database quick-check returnedok. - Current exact baseline: Build 15 daemon SHA
dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0; Build 17 app hash8693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e; one app and one bar process. - R7 original state remains
prepared, SHA94ca7f3650d69cd1c6abbe1240742d4067b8561bda8ec40832a0d44f09ca9132; complete prior metadata SHAc44996a3d54206017ff08d23f2dd865def40c9043c0703dafe3c653d2b6ebc96.
Backup and recovery
- Pinned pre-Build20 database backup remains
/Users/richh/Library/Application Support/Tyrell/backups/20260912-0110-build20-preflight-96a5fc0/tyrell.db, SHAdb29432be4fc962a18436f15f29d1677b10bc7c541d7f78eab6c00f7ecce3c8f. - No database restore occurred; the live additive schema was retained.
- R6, R5, both R7 test stages, and all failure captures remain available for audit.
Undo
The runtime is already at the known-good rollback baseline. To
abandon R7, leave its state=prepared stage inert and do not
run its launcher. Do not remove retained R6/R7 evidence until canonical
review is complete. If R7 is later launched and fails, invoke only its
pinned guard rollback after verifying ownership; its prevalidated
payload restores the exact Build 15 daemon and Build 17 app.
Outstanding owner action
rdmbair15m5 is on AC but its clamshell is closed.
Physically open the lid. The monitor will then require two fresh AC/open
reads and repeat all launch checks before starting a new Build 20 R7
canary. All memory and acceptance clocks restart from zero.