Tyrell Build 20 R7 was launched only on rdmbair15m5
through the hardened rollback-safe, power-protected guard; all
acceptance gates restarted from zero and rollout remains blocked pending
soak evidence.
Detailed changelog
Scope
- Host changed:
rdmbair15m5only. - Project: Tyrell, production mode.
- Tickets:
ISSUE-20260913-09,ISSUE-20260912-14,ISSUE-20260905-23,TASK-20260911-01,ISSUE-20260912-01. - Coordinator:
codex@rdmpw3275m/01a078a7. - No other fleet host was installed, restarted, or authorized for rollout.
- Track B agy was inspected only; no agy process, provider session, or authentication state was changed.
Why this changed
R6 was invalidated by a closed-lid power-envelope boundary and then
exposed ISSUE-20260913-09, a missing local rollback-payload
defect in the canary harness. Exact Build 15 daemon and Build 17 app
were restored. The R7 guard and launcher were hardened and tested to
validate and stage the complete rollback payload before any launch or
rollback mutation. R7 was kept inert until the physical clamshell was
reopened.
At 21:13:50 and 21:14:31 EDT, two fresh readings showed AC power and an open clamshell. A complete fail-closed preflight then passed, authorizing a canary-only launch.
Exact files and installed state changed
- Installed exact signed/notarized Build 20 app at
/Applications/Tyrell.app. - Retained exact Build 17 app rollback at
/Applications/.tyrell-rollbacks/20260913-211712-2c5ca2a674fe/Tyrell.app. - Repointed
/Users/richh/Library/Application Support/Tyrell/bin/tyrelldthrough the pinned service installer to/Users/richh/Library/Application Support/Tyrell/releases/daemon-71bf6122e453/tyrelld. - Updated user LaunchAgent
/Users/richh/Library/LaunchAgents/com.eastcoastscience.tyrelld.plistthrough the pinned installer. - Started hardened guard from
/Users/richh/.tyrell/build20-canary-r7-20260913-96a5fc0/canary_guard.pythrough/Users/richh/.tyrell/build20-canary-r7-20260913-96a5fc0/launch_guard_power_protected.zsh. - Created guard state, samples, inventory, process diagnostics, and installer logs inside the isolated R7 stage.
- Created immutable initial evidence snapshots
state-launch-snapshot.jsonandsamples-launch-snapshot.jsonlinside that stage. - The live database retained its additive
last_seen_atcolumn. No database was restored, replaced, or destructively migrated.
Commands and controls run
- Resolved host identity, ran the mandatory AgentKit preflight, synced fleet mail, and inspected only owned ticket leases.
- Read power/clamshell state twice, separated by a fresh interval.
- Verified the R7 top-level allowlist, state, exact dependency hashes, complete non-symbolic rollback payload, rollback metadata, signatures, stable-path target, and pinned database backup.
- Ran
canary_guard.py rollback-preflightsuccessfully before mutation. - Verified the exact Build 20 app hash, arm64 CDHash, designated requirement, deep strict signature, notarized Gatekeeper assessment, and staple.
- Verified the exact Build 20 daemon hash, universal slices, Team ID, Hardened Runtime, and timestamp.
- Verified exact Build 15/17 baseline identity, both live API planes, live and backup SQLite integrity, one app/bar process, and absence of competing guard/installer/service writers.
- Ran the pinned app installer in dry-run mode, then ran its bounded real promotion.
- Launched only through the pinned R7 power-protected launcher.
- Ran the independent verifier for guard/caffeinate parentage, both sleep assertions, AC/open power envelope, launchd process identity, resolved release path/hash, app/bar cardinality, both APIs, database integrity, and initial samples.
The first combined preflight attempt made no product mutation and
exited because its allowlist expected a different lexical position for
top-level Support. The comparison was corrected and the
full preflight passed. This was a coordinator check issue, not a
candidate failure.
Verification evidence
- Build 20 source commit:
96a5fc012ff754d072aee04a47452fd84e69b2e0. - Build 20 daemon SHA-256:
71bf6122e453315205f3f0dfaf3f1a3a6cf2d99dfe901cda88e7ac79a8112c77. - Build 20 app executable SHA-256:
423871cede8ae6313c486929f544dbee8d1085540b2d37896de6f2c2d4de90fd. - Build 20 arm64
CandidateCDHashFull:37a0081b06af970866e84877cc74524cdac750580d5fad22fb83d92d0eb0aa5c. - Build 20 designated-requirement hash:
9943c03ba47653aab0eacfd8fab8ea70d887d4392fd24832b96bffaa9c502aee. - Hardened guard SHA-256:
f1e5e55fd1aaf9d58a9dfe8a9a3df87e7dd35e351f5ff35d2e5717ab4fe6ad3d. - Power launcher SHA-256:
2ecc1632e5f6ab70ba3bc763c2b3bf10a533a9d0c8f79dd39613d0acaad26448. - Guard PID
99137; guard-owned caffeinate PID99211; exact daemon PID99328. - Daemon process start:
Sun Sep 13 21:17:43 2026; guard state start epoch1789348664.781356. - One Build 20 app process PID
98666and one bar process PID98784at launch verification. - Both
PreventSystemSleepandPreventUserIdleSystemSleepassertions were bound to the guard lifetime; host was AC/open. - Both status and permission planes returned HTTP 200 valid JSON with no 503s.
- Live SQLite quick-check returned
ok, with one additivelast_seen_atcolumn and 153,215 files at initial launch verification. - First two samples retained identical PID/start/path and a 60.021012-second gap. Physical footprint was 255,886,584 then 436,241,920 bytes; lsof rows were 43 then 40; TCP descriptors remained two; endpoint failures remained zero.
- Follow-up pre-warmup samples at 120.653 and 180.658 seconds measured 268,780,960 and 19,711,224 physical bytes with the same identity and healthy endpoints.
- The pre-warmup rise above 300 MiB is diagnostic only and is not a pass or failure verdict.
Gate schedule
- R7 start: 2026-09-13 21:17:44 EDT.
- Warmup end: 2026-09-13 21:27:44 EDT.
- Short gate: 2026-09-13 21:57:44 EDT.
- Six-hour-after-warmup gate: 2026-09-14 03:27:44 EDT.
- Fixed 24-hour gate: 2026-09-14 21:17:44 EDT.
R7 status is SOAKING_NOT_ACCEPTED. No fleet expansion is
authorized. A short pass does not constitute release acceptance.
Backups and preserved evidence
- Complete exact Build 15/17 rollback payload:
/Users/richh/.tyrell/build20-canary-r7-20260913-96a5fc0/prior/. - Retained Build 17 app rollback:
/Applications/.tyrell-rollbacks/20260913-211712-2c5ca2a674fe/Tyrell.app. - Pinned database backup:
/Users/richh/Library/Application Support/Tyrell/backups/20260912-0110-build20-preflight-96a5fc0/tyrell.db, SHA-256db29432be4fc962a18436f15f29d1677b10bc7c541d7f78eab6c00f7ecce3c8f. - Initial state snapshot SHA-256:
6bfb857e1227121ccb3c61994220dd522bf587dc2e0a9e1e6cae691a8b2eb45c. - Initial samples snapshot SHA-256:
2732175481d3ca41ebc2430aabbae50dfc464082fad514100a6921876b54f7e1. - App installer log SHA-256:
19f463361e9fb89e2b8b4527de04085abb54a4509968305353abb511ef8e2ff0. - Daemon installer log SHA-256:
e3e08b70498fb77a428ff8902398cf3fda1b988b85ed603373bbb163b4b81a32.
Undo
If an actual guard failure occurs, preserve the whole R7 stage and let the hardened guard execute its validated rollback. If manual containment is required, stop only the R7 guard process, then invoke the staged guard's rollback command. Independently verify the exact Build 15 daemon hash/path/signature, exact Build 17 app hash/signature, both HTTP status planes, live database quick-check, and final rollback state. Never restore the older pinned database over the live additive database.
Outstanding owner and monitor actions
- Keep the host on AC with the clamshell open; forced restart or power-envelope change remains fail-closed.
- Independently validate short, six-hour-after-warmup, and fixed 24-hour evidence with the pinned validator.
- Require two complete inventories with an unchanged repeat and endpoint overlap, bounded sample gaps, descriptor/socket stability, CPU review, a fresh app probe, and controlled-reboot stable-path proof.
- Keep all Tyrell tickets open until evidence-backed acceptance or independently verified rollback.
- Await canonical accept/reject receipts for Track B agy handoffs; do not resume any parent unless it becomes genuinely incomplete and duplicate-writer checks pass.