rdmbair15m5-changelog-20260914-1348-tyrell-build20-r11-reboot-safe-canary
rdmbair15m5 changelog — Tyrell Build 20 R11 reboot-safe canary
Restored exact accepted Tyrell Build 15/17 after an environmental reboot invalidated R10 continuity, then installed and launched exact Build 20 under a new persistent fail-closed R11 recovery interlock; no other fleet host was promoted.
Scope and reason
- Host changed:
rdmbair15m5, the designated Tyrell canary. - R10 remained product-healthy through 91 samples and 5,401.528
seconds, but a graceful
sessionlogoutd-initiated shutdown at 2026-09-14 12:55:53 EDT terminated its transient guard. Launchd correctly relaunched the durable Build 20 daemon after boot without the guard, exposing a canary-harness defect. ISSUE-20260914-10records the defect. It is not classified as a Build 20 rejection.
Exact runtime and files changed
- Preserved the complete R10 stage and shutdown report off-host before rollback.
- Restored exact Build 15 daemon SHA-256
dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0and Build 17 app executable SHA-2568693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05ebefore preparing R11. - Added R11 stage
/Users/richh/.tyrell/build20-canary-r11-20260914-96a5fc0with exact candidate, scripts, rollback snapshot, tests, policy, guard, and launch/runtime verification artifacts. - Installed exact signed Build 20 app at
/Applications/Tyrell.app, executable SHA-256423871cede8ae6313c486929f544dbee8d1085540b2d37896de6f2c2d4de90fd; installer retained one verified prior app at/Applications/.tyrell-rollbacks/20260914-133906-2c5ca2a674fe/Tyrell.app. - Installed exact Build 20 daemon behind
/Users/richh/Library/Application Support/Tyrell/bin/tyrelld, SHA-25671bf6122e453315205f3f0dfaf3f1a3a6cf2d99dfe901cda88e7ac79a8112c77. - Added
/Users/richh/Library/LaunchAgents/com.eastcoastscience.tyrell-canary-recovery.plist, SHA-256bb1e0d1cbfc8a7a8ad6c91491447d3db2ae18820d5fcb3222428461235145005. - Normal daemon LaunchAgent
com.eastcoastscience.tyrelldremains loaded for the live candidate but is disabled for future automatic starts until acceptance or rollback. - R11 guard writes
state.json,canary-active.marker,guard-heartbeat.json,interlock.json,recovery.log,samples.jsonl,latest.json, inventory output, and boundary captures inside its stage.
Commands and verification
- Verified exact file hashes, strict/deep code signatures,
Team/hardened-runtime identity, universal
x86_64 arm64architectures, pinned dependencies, power/lid state, database backup, rollback payload, live database, launchd state, API state, process identities, and recursive evidence manifests. - Commands included
shasum -a 256,codesign,lipo,zsh -n, Pythonpy_compile,jq,plutil -lint,sqlite3 -readonly,launchctl print,launchctl print-disabled,pmset,ioreg,ps,pgrep, andrsync --checksum. - Nine deterministic reboot-interlock tests passed on this host.
- A disposable real-launchd test passed: disable preserved the live test PID; a disabled job stayed stopped after bootout/bootstrap; enable restored normal launch.
- A 30-iteration live libproc test passed against the accepted
baseline with zero
lsofcalls, maximum 0.059-second duration, 27 descriptors, and two TCP descriptors. - Two bounded functional recovery tests restored exact Build 15/17 from a simulated prior-boot active state; final coverage included guard/policy/daemon identity pinning.
- Before R11 launch, rollback state was exact and both daemon APIs
returned HTTP 200; SQLite
quick_checkreturnedok, and the additivelast_seen_atcolumn was retained. - R11 launched 2026-09-14 13:39:52 EDT: daemon PID 55457/start
13:39:51, guard PID 55257, and guard-owned
caffeinatePID 55320. - Runtime verifier passed AC power, open clamshell, both sleep assertions, exact guard ownership, state/marker/heartbeat/interlock identities, fresh heartbeat, disabled candidate auto-load, and loaded recovery sentinel.
- Three consecutive 60-second sentinel cycles returned
decision=monitor,boot_matches=true,candidate_active=true, andservice_disabled=true. - Third sample at elapsed 120.737 seconds: 18,187,464 physical bytes, 26 descriptors, two TCP descriptors, both status APIs HTTP 200/valid JSON, and all 16 concurrent permission probes HTTP 200/valid JSON.
- Canonical launch evidence is
/Users/richh/dev/_handoff/tyrell-build20-memory-20260912/canary-r11-launch-20260914-1339onrdmsm4x. Its frozen stage manifest is SHA-256d01025f340a338e5c48f48a421bf77a496804823df637a1ba2013c3f55636cb0; its frozen harness manifest is SHA-256247d9ab09871bb39389671781116288e8e4a5236cf6a4665c131aa96c6fefd76; canonical and local copies matched.
Recovery and undo
- R11 persists a user LaunchAgent sentinel across login/reboot. A boot-session mismatch, dead guard, missing/corrupt heartbeat, or heartbeat older than 180 seconds triggers the exact prevalidated rollback.
- Guard/policy/daemon identity drift leaves the normal candidate service disabled and requires inspection rather than accepting or launching an ambiguous artifact.
- Manual bounded undo command:
/opt/homebrew/bin/python3.14 /Users/richh/.tyrell/build20-canary-r11-20260914-96a5fc0/canary_guard.py rollback. - Rollback restores exact Build 15 daemon plus Build 17 app, re-enables normal daemon launch, unloads/removes the recovery sentinel, retains the compatible additive database schema, and verifies endpoint health.
Outstanding
- R11 is
SOAKING_NOT_ACCEPTED; short gate is due near 2026-09-14 14:19:52 EDT, six-hour-after-warmup gate near 19:49:52 EDT, and fixed 24-hour gate near 2026-09-15 13:39:52 EDT. - Inventory-repeat, CPU, app, and controlled-reboot acceptance remain pending.
- No fleet expansion, production deployment, or release acceptance is authorized.