rdmpw3275m-changelog-20260906-1835-tyrelld-stable-runtime-and-build16
rdmpw3275m-changelog-20260906-1835-tyrelld-stable-runtime-and-build16
Restored the local Tyrell control plane from a retained signed daemon, moved launchd off mutable SwiftPM output, and prepared/pushed the tested Build 16 source fix for canonical signing and canary.
Scope
- Runtime host changed:
rdmpw3275monly. - Source work: isolated worktree
/Users/richh/dev/_worktrees/tyrell-tyrelld-stable-launch-20260906, branchcodex/tyrelld-stable-launch-20260906. - Canonical
/Users/richh/dev/apps/tyrellonrdmsm4xwas inspected read-only and not modified. - Local dirty
/Users/richh/dev/apps/tyrellwas inspected read-only and not modified. - Updated the Tyrell status entry in canonical iCloud
PROJECTS.mdwith the bounded incident/source/pending-gates checkpoint. - Copied this changelog additively to the canonical archive on
rdmsm4x; the local and canonical copies were initially SHA-256-identical. - No fleet deployment, canary acceptance, release, credential, TCC, database, user-history, or provider-data change was made.
Cause
The installed LaunchAgent pointed at
/Users/richh/dev/apps/Tyrell/.build/release/tyrelld.
SwiftPM had rewritten that alias to out/Products/Release,
whose target no longer existed. After the 2026-09-06 reboot, launchd
could not spawn it and recorded exit 78 (EX_CONFIG). Both
loopback status listeners were absent, which caused Tyrell.app to report
Offline. Tailscale was also stopped and blocked remote reachability, but
was secondary to the local loopback outage.
Local changes
- Ran
/usr/local/bin/tailscale up;tailscale debug prefsnow reportsWantRunning=true. - Preserved the failed pre-change LaunchAgent plist at:
/Users/richh/Library/Application Support/Tyrell/backups/ISSUE-20260905-23-20260906/com.eastcoastscience.tyrelld.plist.before-stable-path(SHA-256b94365aabefa6cf72e7490fb7e1c42e0ca874d533c477ba8d82ce07431136bd0). - Retained signed universal recovery input:
/Users/richh/Library/Application Support/Tyrell/releases/b15-dbc440bd54b8/tyrelld. - Ran:
zsh scripts/install_service.zsh --client --binary '/Users/richh/Library/Application Support/Tyrell/releases/b15-dbc440bd54b8/tyrelld'from the isolated worktree. - Installed managed stable path:
/Users/richh/Library/Application Support/Tyrell/bin/tyrelld->/Users/richh/Library/Application Support/Tyrell/releases/daemon-dbc440bd54b8/tyrelld. - Re-rendered
/Users/richh/Library/LaunchAgents/com.eastcoastscience.tyrelld.plistsoProgramArguments[0]names that stable path. - Bootstrapped
gui/501/com.eastcoastscience.tyrelld; observed PID 52142.
Source files changed
Sources/tyrell/Tyrell.swiftSources/tyrell-app/SettingsView.swiftSupport/com.eastcoastscience.tyrelld.plist.templatescripts/install_service.zshscripts/lib/tyrelld_lifecycle.zsh(new)scripts/onboard_permissions.zshTests/ScriptTests/tyrelld_stable_install_contract_test.zsh(new)docs/QA-CHECKLIST.mdISSUES.mdSESSION-STATE.md
Commits pushed to git.ecs0.net:git/apps/Tyrell.git:
b57d5bd92c2543a8607578a4f8fd23e960737c7f— Swift 6.3.3 Build 16 compiler unblock.869503aa054c9d762541c0359d07a8aefb2f2187— stable signed daemon staging and regression contract.f82d560f749eb60b0963809da28d77aff841bfbc— outage, validation, rollback, and handoff record.
Bugs and coordination
- Existing
ISSUE-20260905-23was claimed and updated with the confirmed cause, local recovery evidence, stable-path source fix, and deliberately pending fleet gates. It remains in progress. - Filed
ISSUE-20260906-14for the separate deterministic Swift 6.3.3 Build 16 compiler failures. Resolved after fixes atb57d5bdand successful builds/tests. - Sent high-priority canonical build/sign/canary request
20260906-183131-65BA0096to existingclaude@rdmsm4xandcodex@rdmsm4xlanes. Current source head isf82d560. - Verified the request files exist on
rdmsm4xand both provider CLIs report authenticated by exit code; no provider acknowledgment or work acceptance has yet been received. - Created thread heartbeat automation
finish-tyrell-build-16, every 15 minutes, to continue only after exact signed app/daemon receipts and designated-canary acceptance; it stays quiet on unchanged state and pauses after completion.
Verification evidence
launchctl print gui/501/com.eastcoastscience.tyrelld:state = running, program is the managed stable path, PID 52142,last exit code = (never exited).lipo -archson the running managed daemon:x86_64 arm64.- Managed daemon SHA-256:
dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0. - Ports 43117 and 43118: HTTP 200 in three of three consecutive probes
each;
lsofattributes both listeners to PID 52142. - Tyrell.app PID 2903 and TyrellBar PID 3858 remained running.
- Remote hub status: rdmsm4x PID 3543 answers HTTP 200, but its
current plist still points into
.build; that risk is not called fixed. - Seven shell contract tests passed, including the new test that deletes the source build binary, runs the managed copy, upgrades it, retains the rollback release, and refuses an unmanaged stable-path replacement.
- Apple Swift 6.3.3 universal release builds succeeded for
tyrelld,tyrell, andtyrell-app; each reportsx86_64 arm64. - Unsigned local Build 16
tyrelldcandidate SHA-256:39846ce4c6ddc3c7d09aa23dc453c9f9a0d59b1f3c2a81f32c2b40f7ed81f310. It was not installed or represented as a release. - Deterministic filtered test log:
/Users/richh/scripts/logs/tyrell_build16_filtered_tests_20260906-1828.log. Exit 0; XCTest 533 executed, 1 skipped, 0 failures; Swift Testing 632 tests in 54 suites passed. - Unfiltered environment-dependent red evidence remains explicit: the
installed Build 15 spoke lacks the newer
/api/fleet/usageroute expected by one live test, and/tmp/providers_dashboard_fixture.pngis absent for one visual-fixture test. - Isolated unsigned Build 16 daemon smoke on temporary ports
43231/43232 returned HTTP 200 for data status, control status, and
/api/fleet/usage; its PID, listeners, and temporary workspace were removed afterward. Log:/Users/richh/scripts/logs/tyrelld_build16_isolated_smoke_20260906.log. git diff --check, script syntax, contract tests, and pushed-branch clean status passed.
Undo / recovery
- The prior LaunchAgent plist is preserved at the backup path above; do not restore it unless its dead build-tree target is also deliberately recovered.
- To roll the managed daemon back without returning to
.build, atomically repoint/Users/richh/Library/Application Support/Tyrell/bin/tyrelldto an earlier retained signed release, then bootout/bootstrap the LaunchAgent and re-run both loopback status probes. - To undo source work, revert
f82d560,869503a, andb57d5bdin a new isolated branch. Do not rewrite published history. tailscale downwould undo the local Tailscale state change, but doing so would intentionally remove tailnet connectivity and is not recommended while Tyrell is expected online.
Outstanding owner / canonical actions
- One authorized GUI session on
rdmsm4xmust independently integrate/review, build universal Build 16, sign with TeamZU2882L4HTand Hardened Runtime, and return an artifact receipt. - The exact signed artifact must pass the designated
rdmbair15m5canary before any other host. - After canary acceptance, install that identical artifact through the managed stable path on all six hosts; verify hash, signature, slices, launchd program path, role, both status planes, and rollback.
- Complete the existing daemon RSS-slope acceptance window. Until
these steps pass, Build 16 is not installed, deployed, canary-accepted,
or released, and
ISSUE-20260905-23must remain open.