rdmpw3275m-changelog-20260909-1436-tyrell-build16-exact-fleet-rollout
rdmpw3275m changelog — Tyrell Build 16 exact fleet rollout
Tyrell 0.2.0 Build 16 and one exact signed universal Build 16
tyrelld artifact are now installed and running on all six
fleet Macs; the daemon rollout corrected the earlier false-green
per-host deployment by moving every host to the same immutable managed
path and hash.
Scope
- Controller host:
rdmpw3275m. - Runtime hosts changed:
rdmsm4x,rdmbair15m5,rdmbair13m5,rdmpw3265m,rdmpw3275m, andjdmbair13m5. - No Tyrell source file, Git ref, database, store, credential, TCC record, user history, or provider session database was changed by this remediation.
- The canonical source tree was inspected read-only. Stable installer
source remains published at commit
869503aa054c9d762541c0359d07a8aefb2f2187for canonical integration.
Trigger and corrected false green
- The canonical Build 16 app rollout installed a valid signed
universal
/Applications/Tyrell.appon the fleet. - Its subsequent native daemon deployment rebuilt and installed from
each host's mutable
.buildtree. On both Intel Mac Pros the result was x86_64-only and unsigned, while all five non-contained hosts still launched from/Users/richh/dev/apps/Tyrell/.build/release/tyrelld. - The exact rdmpw3275m unsafe state and rollback evidence are retained
under
/Users/richh/.devmon/incidents/20260909-135703-tyrelld-unsigned-mutable-runtime/and documented inrdmpw3275m-changelog-20260909-1408-tyrelld-unsigned-runtime-rollback.md. - The existing bug is tracked by
ISSUE-20260905-23; no duplicate issue was opened. The ticket received the exact false-green and corrected-rollout evidence.
Canonical artifacts
Tyrell.app
- Version:
0.2.0. - Build:
16. - Executable SHA-256:
3150151bbefd1f4e76820df647208775f19709b595895b8ee0dbbf074a3be5c8. - Architectures:
x86_64 arm64. - Team Identifier:
ZU2882L4HT. - Hardened Runtime and strict deep code-signature verification: valid.
tyrelld
- Source artifact: the signed universal Build 16 daemon produced on
canonical
rdmsm4x. - SHA-256:
69c56725e9f7708b4c7c803a7ae4639a4f470e2f6c16180730e4de780cf86eb2. - Architectures:
x86_64 arm64. - Slice CDHashes: x86_64
d9fe1b76f9b81ecdd61c2082fbfa8f5575f6ea0f; arm64edf415c17adfcfae9d606422de605134ae799d0c. - Team Identifier:
ZU2882L4HT. - Signer: Apple Development identity for Richard Doty.
- Hardened Runtime
15.0.0and strict code-signature verification: valid.
Pre-rollout verification
- Copied the canonical daemon to
/Users/richh/Documents/ChatGPT/rdmpw3275m/handoff/tyrell-build16-universal-daemon-20260909/tyrelldand reproduced its exact hash, both architectures, signing team, Hardened Runtime, and strict signature locally. - Ran an isolated x86_64-host smoke with a separate database/store and
observation disabled on ports
43231and43232. Data status, control status, and/api/fleet/usageeach returned HTTP 200 while the candidate remained alive; the process was terminated after the check. - Packaged the candidate with the stable installer implementation from
commit
869503a; the package is retained in the same handoff directory.
Designated canary
- Canary host:
rdmbair15m5. - Pre-canary plist and prior daemon preserved at
/Users/richh/.devmon/incidents/20260909-1425-tyrelld-build16-exact-canary/on that host. - Installed the exact daemon hash through the hardened installer at
2026-09-09 14:24:57 EDT. - Immediate and 90-second checks reproduced: stable managed path,
exact hash, both architectures, strict signature, Team Identifier,
launchd runs
1, last exitnever exited, PID stable, 39 open-file rows, and HTTP 200 on local ports43117and43118. - Designated-host acceptance receipt:
20260909-142647-4F22DCFF.
Fleet rollout
The exact canary-accepted daemon was staged and installed with explicit client/server roles:
rdmpw3275mclient at14:27:36 EDT.rdmpw3265mclient at14:28:26 EDT.rdmbair13m5client at14:29:18 EDT.rdmsm4xserver at14:30:10 EDT.jdmbair13m5client at14:32:12 EDT, reached throughrdmsm4xafter the controller's direct path timed out.rdmbair15m5was already accepted as the designated canary.
Every host now launches:
/Users/richh/Library/Application Support/Tyrell/bin/tyrelld
which resolves to:
/Users/richh/Library/Application Support/Tyrell/releases/daemon-69c56725e9f7/tyrelld
Independent post-rollout matrix
- All six installed
Tyrell.appbundles report Build16, executable hash3150151b..., architecturesx86_64 arm64, strict signature valid, TeamZU2882L4HT, and a runningTyrellprocess from/Applications/Tyrell.app. - All six LaunchAgents name the stable managed daemon path, not
.build. - All six daemon paths resolve to the
daemon-69c56725e9f7release and reproduce SHA-25669c56725.... - All six daemons report architectures
x86_64 arm64, strict signature valid, TeamZU2882L4HT, launchd runs1, and last exitnever exitedat verification time. - Both local status endpoints, ports
43117and43118, returned HTTP 200 on every host. - The canonical server's
/api/fleet/usagereturned HTTP 200. - Final rollout receipt broadcast:
20260909-143519-26263B8C.
Backups and undo
rdmpw3275m: signed Build 15 remains atreleases/daemon-dbc440bd54b8/tyrelld; unsafe false-green evidence remains in the20260909-135703incident directory.rdmbair15m5: pre-canary state retained in20260909-1425-tyrelld-build16-exact-canary.rdmpw3265m: pre-rollout state retained in20260909-1428-tyrelld-build16-exact-rollout.rdmbair13m5: pre-rollout state retained in20260909-1429-tyrelld-build16-exact-rollout.rdmsm4x: pre-rollout state retained in20260909-1430-tyrelld-build16-exact-rollout.jdmbair13m5: pre-rollout state retained in20260909-1432-tyrelld-build16-exact-rollout.- The stable lifecycle retains prior hash-addressed releases. To undo,
rerun the same hardened installer with a retained signed universal
candidate and the host's explicit
--serveror--clientrole. - No prior artifact or rollback bundle was deleted.
Outstanding work
- Continue the long-duration RSS/memory-slope acceptance window; immediate launch health is not long-soak proof.
- Canonical owner must integrate commit
869503aor an independently equivalent stable-path/signature gate so a futuredeploy_fleet.zshrun cannot restore mutable or unsigned per-host daemons. - Correct the canonical false-green claim that Intel daemon deployment was complete before exact signing/path verification.
- Continue monitoring Track B local-agy handoffs until canonical
owners return explicit accept/reject receipts; no local agy parent is
eligible for resume and no provider 429 or
RESOURCE_EXHAUSTEDhas occurred.