rdmbair15m5-changelog-20260914-1018-tyrell-build20-r8-canary-launch
Launched exact signed Tyrell Build 20 R8 on the single designated canary under the hardened fail-closed guard; the run is healthy and sampling but not accepted or expanded.
Scope
- Changed host:
rdmbair15m5only. - Coordinating host:
rdmpw3275m. - No other fleet host was installed, restarted, or promoted.
Exact state changed
- Promoted exact notarized Build 20 to
/Applications/Tyrell.app. - Retained exact Build 17 rollback at
/Applications/.tyrell-rollbacks/20260914-101514-2c5ca2a674fe/Tyrell.app. - Updated
/Users/richh/Library/Application Support/Tyrell/bin/tyrelldto the exact hash-addressed release/Users/richh/Library/Application Support/Tyrell/releases/daemon-71bf6122e453/tyrelld. - Re-rendered
/Users/richh/Library/LaunchAgents/com.eastcoastscience.tyrelld.plistthrough the pinned service installer. - Updated the prepared R8 stage at
/Users/richh/.tyrell/build20-canary-r8-20260913-96a5fc0:state.json,migration.json,samples.jsonl,latest.json,inventory.log,guard-launch.log, anddaemon-install.log. - Added immutable launch snapshots
samples-launch-snapshot.jsonl,state-launch-snapshot.json, andlatest-launch-snapshot.jsonto that stage. - The live database retained its additive schema; no database restore occurred.
Commands run
- Full read-only allowlist, hash, signature, Gatekeeper, rollback-payload, process-owner, API, live-database, and pinned-backup preflight.
/bin/zsh .../scripts/install_app_local.zsh --bundle .../candidate/Tyrell.app --expected-hash 423871cede8ae6313c486929f544dbee8d1085540b2d37896de6f2c2d4de90fd --expected-cdhash 37a0081b06af970866e84877cc74524cdac750580d5fad22fb83d92d0eb0aa5c --target-user richh --accept-designated-requirement-change --dry-run./usr/bin/sudo -n /bin/zsh .../scripts/install_app_local.zshwith the same exact identity arguments for the bounded application promotion./usr/bin/nohup /bin/zsh .../launch_guard_power_protected.zshfor the guarded daemon launch..../verify_guard_power_protected.zsh,launchctl print,lsof, SHA-256 checks, both status probes, and SQLite read-only quick checks for post-launch verification.
Verification evidence
- Two fresh readings and the final pre-mutation reading showed AC power and an open clamshell.
- Build 20 daemon SHA-256:
71bf6122e453315205f3f0dfaf3f1a3a6cf2d99dfe901cda88e7ac79a8112c77. - Build 20 app executable SHA-256:
423871cede8ae6313c486929f544dbee8d1085540b2d37896de6f2c2d4de90fd. - Gatekeeper: accepted,
source=Notarized Developer ID. - Guard PID
38849; child caffeinate PID38910; both sleep assertions verified. - Daemon PID
39036; startMon Sep 14 10:15:22 2026; launchdruns=1, never exited; exact hash-addressed text path. - App PID
38732; TyrellBar PID38757; exactly one of each from/Applications/Tyrell.app. - Both ports 43117 and 43118 returned HTTP 200 with valid JSON.
- Live database quick-check
ok, 153,325 files, one additivelast_seen_atcolumn. - Initial three samples retained one PID/start/path, AC/open, two TCP descriptors, no status failures, no permission failures, and no 503 responses.
- Immutable launch-snapshot SHA-256:
849f8addf47bf2b2d00c6091bd5d83d9a7f604c163793d35cebb95ed21af80c4.
Backups and recovery
- Exact application rollback:
/Applications/.tyrell-rollbacks/20260914-101514-2c5ca2a674fe/Tyrell.app. - Complete rollback payload:
/Users/richh/.tyrell/build20-canary-r8-20260913-96a5fc0/priorandprior.json. - Pinned pre-migration database backup:
/Users/richh/Library/Application Support/Tyrell/backups/20260912-0110-build20-preflight-96a5fc0/tyrell.db, SHA-256db29432be4fc962a18436f15f29d1677b10bc7c541d7f78eab6c00f7ecce3c8f. - Automatic undo: the guard validates the complete rollback payload
first, then restores exact Build 15 daemon and Build 17 app on a
failure. For a bounded operator rollback, use the pinned Python 3.14
runtime with
canary_guard.py rollback, then independently verify both APIs, app/daemon identities, live database integrity, and absence of guard assertions. - Never overwrite the live additive database with the pinned pre-migration backup.
Outstanding owner actions
- Keep
rdmbair15m5physically open and on AC. - Short gate is due at 10:55:23 EDT; six-hour gate at 16:25:23 EDT; fixed 24-hour gate at 10:15:23 EDT on 2026-09-15.
- Do not expand beyond this canary until memory, inventory, CPU, application, and controlled-reboot gates all pass.
- This SSH session cannot write Apple Notes because its launchd
manager is
Background; a GUI-session agent must run/Users/richh/scripts/notes_changelog.zshagainst this file.