rdmbair15m5-changelog-20260923-0930-feat-20260905-22-tyrell-guards-and-load-policy
rdmbair15m5-changelog-20260923-0930-feat-20260905-22-tyrell-guards-and-load-policy
One-line summary: Absorbed 5 uncoordinated fleet
guards into TyrellCore (FleetGuardCoordinator,
ProcessHoldManager, FleetLoadPolicy),
eliminating destructive SIGKILL call sites and implementing cooperative
TTL-backed process holds (SIGSTOP/SIGCONT),
resolving FEAT-20260905-22.
1. Scope
- Hosts Affected: Fleet-wide (
rdmsm4x,rdmbair13m5,rdmbair15m5,jdmbair13m5,rdmpw3265m,rdmpw3275m). - Repositories:
apps/Tyrell(git.ecs0.net:git/apps/Tyrell.git). - Tickets:
FEAT-20260905-22(resolved),EPIC-20260905-03,EPIC-20260905-01,ISSUE-20260905-08.
2. Exact Files Touched
Sources/TyrellCore/Guards/ProcessHoldManager.swift(new, 225 lines):- Cooperative process suspension (
SIGSTOP) and resumption (SIGCONT) with declared TTL. - Automatic expiration watchdog (
reapExpiredHolds) ensuring suspended processes are safely resumed if TTL expires. - Strictly 0
SIGKILLcall sites.
- Cooperative process suspension (
Sources/TyrellCore/Guards/FleetLoadPolicy.swift(new, 211 lines):- Host hardware profile classification (
rdmsm4x,rdmpw*, laptops). - Load condition evaluation:
.normal,.elevated,.runaway,.storm,.ioStall. - Reconciles CPU storm vs I/O stall: high load average with CPU idle
>= 65% classified as
ioStall(report-only; never kill or holdbackupd). - Process safety protection rules: agent harnesses
(
claude,codex,agy), shells (zsh,bash,fish), GUI apps, and compilers/build tools are strictly protected.
- Host hardware profile classification (
Sources/TyrellCore/Guards/FleetGuardCoordinator.swift(new, 463 lines):- Local system metrics sampling (POSIX
getloadavg,mach_host_self,host_statistics64,vm.swapusage). - Leak-free, timeout-bounded subprocess execution using
SubprocessRunner. - Replaces permanent ReplicantDB daemon kill loop with load-gated TTL holds (120s).
- Infrastructure self-healing via
launchctl kickstart -k(neverbootout + disable).
- Local system metrics sampling (POSIX
Sources/tyrell/Tyrell.swift(modified, +132 lines):- Subcommands:
tyrell fleet guard [--status] [--evaluate] [--holds] [--release-holds] [--dry-run] [--json]. - Subcommands:
tyrell fleet hold <pid> [--ttl <seconds>] [--reason <reason>]andtyrell fleet resume <pid>. - Table rendering functions
printGuardEvaluationReportandprintActiveHoldsReport.
- Subcommands:
Sources/tyrelld/Daemon.swift(modified, +38 lines):- Added background periodic 90s guard task executing
FleetGuardCoordinator.shared.evaluateLocalGuard(dryRun: false). - Registered REST endpoints
/api/fleet/guard/statusand/api/fleet/guard/holds.
- Added background periodic 90s guard task executing
Package.swift(modified):- Excluded
Guardsdirectory fromTyrellRemoteSupporttarget.
- Excluded
Tests/TyrellCoreTests/FleetGuardCoordinatorTests.swift(new, 313 lines):- 6 unit test cases covering 0 SIGKILL static assertion, hold lifecycle & TTL expiration, safety invariants, storm vs IO stall discrimination, ReplicantDB TTL gating, and report serialization.
3. Commands Run
# Run unit tests
build_slot.zsh wrap swift test --package-path apps/Tyrell --filter FleetGuardCoordinatorTests
# Commit & push to remotes
git -C apps/Tyrell commit -m "feat(guards): absorb load guard, realtime guard, stormguard, and agentheal into Tyrell per FEAT-20260905-22"
git -C apps/Tyrell push origin main
git -C apps/Tyrell push backup main
# Fast-forward canonical on rdmsm4x
ssh rdmsm4x 'git -C ~/dev/apps/Tyrell fetch fleet && git -C ~/dev/apps/Tyrell merge --ff-only fleet/main'
# Test run on rdmsm4x
ssh rdmsm4x 'build_slot.zsh wrap swift test --package-path ~/dev/apps/Tyrell --filter FleetGuardCoordinatorTests'
ssh rdmsm4x 'build_slot.zsh wrap swift run --package-path ~/dev/apps/Tyrell tyrell fleet guard'
# Resolve ticket on canonical store
ssh rdmsm4x 'ticket resolve FEAT-20260905-22 ...'4. Verification Evidence
- Local Unit Tests (
rdmbair15m5): 6/6 tests passed (0 failures, 0.028s). - Remote Unit Tests (
rdmsm4x): 6/6 tests passed (0 failures, 0.006s). - Static Code Assertion
(
testZeroSIGKILLCallSitesInGuardPolicy): Passed. 0 instances ofSIGKILL,kill -9, or-KILLin executable guard code. - CLI Execution:
tyrell fleet guardexecuted live onrdmbair15m5andrdmsm4x, accurately assessing system conditions, displaying CPU/memory/uninterruptible wait metrics, and cleanly executing TTL holds without collateral damage. - Commit:
27da046onmain.
5. Backup Locations & How to Undo
- Git Commit:
27da046inapps/Tyrell. - To Undo:
git -C apps/Tyrell revert 27da046git -C apps/Tyrell push origin main && git -C apps/Tyrell push backup main
6. Outstanding Owner Actions
- None. After a 14-day observation period showing sustained agreement,
legacy guard launchd jobs (
fleet-load-guard,fleet-realtime-guard,stormguard,agentheal) can be archived.