rdmbair15m5-changelog-20260913-2208-tyrell-build20-r7-lid-rollback-r8-prepared
Tyrell Build 20 R7 failed closed before its short gate when the canary lid closed; exact Build 15/17 was independently verified, the complete R7 stage was preserved canonically, and a fresh R8 stage is prepared but not launched.
Detailed changelog
Scope
- Host changed:
rdmbair15m5only. - Project: Tyrell, production mode.
- Tickets:
ISSUE-20260912-14,ISSUE-20260913-09,TASK-20260911-01,ISSUE-20260912-01,ISSUE-20260905-23. - Coordinator:
codex@rdmpw3275m/01a078a7. - Canonical evidence was copied additively to
rdmsm4x. - No other fleet host was installed, restarted, or authorized for rollout.
- Track B agy was inspected only; no agy process or authentication state changed.
Incident and classification
- R7 launched exact Build 20 at 21:17:43 EDT under the hardened continuous AC/open guard.
- At 21:52:53 EDT, before the 21:57:44 short gate, the guard detected
AppleClamshellState = Yes. - The guard failed closed and completed its hardened rollback with
daemon_healthy=trueandapp_rollback_rc=0. - R7 is
INCONCLUSIVE_ENVIRONMENTAL_INTERRUPTION, not a Build 20 product-memory rejection. - All R7 acceptance clocks are void.
Runtime and evidence changed
- Restored exact Build 15 daemon behind
/Users/richh/Library/Application Support/Tyrell/bin/tyrelld. - Restored exact Build 17 app at
/Applications/Tyrell.app. - Preserved the complete R7 stage in place at
/Users/richh/.tyrell/build20-canary-r7-20260913-96a5fc0. - Copied the complete R7 stage additively to canonical
/Users/richh/dev/_handoff/tyrell-build20-memory-20260912/canary-r7-lid-closure-20260913-2152/build20-canary-r7-20260913-96a5fc0. - Created fresh inert R8 stage
/Users/richh/.tyrell/build20-canary-r8-20260913-96a5fc0with exact immutable candidate inputs and a newly captured complete Build 15/17 rollback payload. - The live additive database was retained. No database was restored or replaced.
Commands and controls run
- Ran mandatory AgentKit preflight and fleet-mail synchronization.
- Read R7 state, guard log, samples, failure footprint/vmmap, app rollback log, process state, launchd state, power state, APIs, signatures, stable-link identity, application identity, and live database.
- Recomputed R7 sample continuity, process identity, envelope, endpoint, descriptor, socket, inventory, and physical-footprint summaries from raw JSONL.
- Copied the complete R7 directory over an SSH tar stream into a new canonical evidence root.
- Independently hashed every regular file plus relative path, mode, size, directory, and symlink identity on source and destination.
- Created R8 from only the immutable candidate, hardened guard/launcher/verifier, policy/validator, installers, and templates.
- Ran R8
prepare, Python compilation, zsh syntax checks, exact hash checks, and rollback-payload checks. - Confirmed AC power but a physically closed clamshell; left R8 inert.
Verification evidence
- R7 accepted samples: 35 over 2,040.892401 seconds; maximum gap 60.041460 seconds.
- One exact PID/start/path; all accepted samples were
rdmbair15m5, AC, open. - Zero status failures, permission failures, or HTTP 503 responses.
- Physical bytes first/last: 255,886,584 / 61,146,408; failure-boundary capture 106,464,504; diagnostic peak 509,232,640.
- lsof rows 43 to 42, observed range 40 to 44; TCP descriptors always two.
- Only inventory pass 1 completed; unchanged repeat false; no short-gate receipt exists.
- Exact rollback daemon SHA-256
dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0. - Exact rollback app SHA-256
8693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e. - Launchd PID
38113, runs one, never exited; both APIs HTTP 200 valid JSON. - Database quick-check
ok, 153,240 files, one additivelast_seen_atcolumn. - No R7 guard or guard-owned caffeinate remained after rollback.
- Complete source/canonical R7 manifest SHA-256
9484defa0c7af92a64bfe4fe23e08aba5e35a501f9da076fb274a6400f9bd424: 53 files, 30 directories, zero symlinks, 275,044,293 bytes. - R8 state SHA-256
267db531e1472b2a99c2dd6f1c32be5af68e9f2689509053413116532f7d0a55. - R8 prior metadata SHA-256
0ebb8ef0d751548e458d7828141cf7ec8eb078aad8905a23676b760c198a8be6.
Backups and preserved evidence
- Complete R7 stage remains on canary and canonical hub.
- R8 contains a complete exact Build 15/17
prior/rollback payload. - Pinned pre-migration database backup remains unchanged at
/Users/richh/Library/Application Support/Tyrell/backups/20260912-0110-build20-preflight-96a5fc0/tyrell.db, SHA-256db29432be4fc962a18436f15f29d1677b10bc7c541d7f78eab6c00f7ecce3c8f.
Undo
No undo is required for the R7 rollback: exact baseline service and app are already healthy. R8 is inert and can be left in place for the next verified launch. If R8 must be abandoned, retain it as evidence; do not delete or overwrite R7 or its canonical copy. Never restore the older database over the live additive database.
Outstanding work
- Physical gate: open the
rdmbair15m5clamshell while it remains on AC. - Require two new AC/open observations and the complete R8 launch preflight.
- Launch exact Build 20 only through the pinned R8 launcher.
- Restart every short, six-hour, and 24-hour clock from the next actual daemon start.
- No fleet expansion before every acceptance gate, repeated inventory, CPU, fresh-app, and controlled-reboot proof passes.