Fleet changelogs · dev.ecs0.net
rdmpw3275m-changelog-20260909-1532-tyrelld-build16-rejected-full-daemon-rollback

rdmpw3275m changelog — Tyrell Build 16 daemon rejected and rolled back fleet-wide

The exact signed universal Build 16 tyrelld candidate failed fleet production acceptance and was removed from service on all six Macs. Four hosts breached the 300 MB RSS acceptance ceiling, and the designated canary subsequently stopped answering both APIs while its process remained alive and accumulated 511 open-file rows. All six daemons were returned to the exact signed universal Build 15 binary at the managed stable path. Three repeated post-rollback checks found stable PIDs, 39–42 open-file rows, and HTTP 200 on both daemon ports on every host. The signed Build 16 GUI app remains installed because the observed failure is in the daemon.

Scope

Acceptance failure

The unmodified 30-minute acceptance probe completed with each original PID and flat descriptor count, but four of six hosts exceeded the absolute 300 MB RSS ceiling:

Host RSS slope End RSS FD delta Restarts Result
jdmbair13m5 -2.186 MB/min 109 MB 0 0 PASS
rdmbair13m5 -3.251 MB/min 399 MB 0 0 FAIL
rdmbair15m5 -13.006 MB/min 119 MB 0 0 PASS at probe end; later invalidated
rdmpw3265m +2.112 MB/min 519 MB 0 0 FAIL
rdmpw3275m +9.339 MB/min 1,904 MB 0 0 FAIL
rdmsm4x -6.206 MB/min 2,064 MB 0 0 FAIL

The 30-minute slope metric is independently known to be too short for bursty growth (ISSUES.md #69), and the reported sessions=0 field is a known instrumentation defect (ISSUES.md #59). Neither caveat clears the four unambiguous absolute RSS failures.

Raw probe logs are retained at:

/Users/richh/.devmon/incidents/20260909-1515-tyrelld-build16-rss-acceptance-fail/

SHA-256 checks:

Designated-canary endpoint failure

At approximately 15:26 EDT, after the nominal 30-minute probe pass, rdmbair15m5 candidate PID 40384 remained alive and launchd still reported runs = 1 and last exit = (never exited), but both local ports 43117 and 43118 stopped responding. RSS was only 243248 KB, so this was not an RSS-threshold kill.

The exact lsof capture contained 511 rows, including 433 TCP entries in CLOSED and 31 in CLOSE_WAIT, compared with 40 rows at probe completion minutes earlier. This late failure invalidates both the earlier 90-second canary receipt and the apparent 30-minute canary pass.

The complete canary capture is retained on rdmbair15m5 at:

/Users/richh/.devmon/incidents/20260909-1527-tyrelld-build16-canary-socket-leak/

Key SHA-256 checks:

The process sample showed multiple concurrent request tasks blocked in ECS0HTTPServer.processRawHTTP, through the Tyrell route handler, in AgentPermissionCollector.readRows(at:) at sqlite3_open_v2. Because the server closes a connection only after the async handler returns, repeated /api/agent-permissions polling can retain accepted connections while the TCC database operation blocks. This is the leading source-level hypothesis, not yet a verified fix.

Containment and rollback

Representative commands used for capture, artifact verification, rollback, and verification were:

for f in /Users/richh/.devmon/incidents/20260909-1515-tyrelld-build16-rss-acceptance-fail/*.log; do
  printf '%s ' "$(basename "$f" .log)"
  rg 'slope_MB_per_min=' "$f" | head -n 1
done

shasum -a 256 "$HOME/Library/Application Support/Tyrell/releases/daemon-dbc440bd54b8/tyrelld"
lipo -archs "$HOME/Library/Application Support/Tyrell/releases/daemon-dbc440bd54b8/tyrelld"
codesign --verify --strict --verbose=2 "$HOME/Library/Application Support/Tyrell/releases/daemon-dbc440bd54b8/tyrelld"

zsh package/scripts/install_service.zsh --client --binary "$HOME/Library/Application Support/Tyrell/releases/daemon-dbc440bd54b8/tyrelld"
zsh package/scripts/install_service.zsh --server --binary "$HOME/Library/Application Support/Tyrell/releases/daemon-dbc440bd54b8/tyrelld"

launchctl print "gui/$(id -u)/com.eastcoastscience.tyrelld"
lsof -nP -p "$(pgrep -x tyrelld)"
curl --max-time 5 -o /dev/null -w '%{http_code}\n' http://127.0.0.1:43117/api/status
curl --max-time 5 -o /dev/null -w '%{http_code}\n' http://127.0.0.1:43118/api/status

Post-rollback verification

At the final three repeated fleet probes, every daemon held its replacement PID, launchd reported it running, both local APIs returned HTTP 200, and the canonical server's /api/fleet/usage returned HTTP 200.

Host Replacement PID Daemon SHA-256 Managed target lsof rows 43117 43118
rdmsm4x 5739 dbc440bd... releases/daemon-dbc440bd54b8/tyrelld 39–42 200 200
rdmbair15m5 80686 dbc440bd... releases/daemon-dbc440bd54b8/tyrelld 39–42 200 200
rdmbair13m5 51090 dbc440bd... releases/daemon-dbc440bd54b8/tyrelld 39–42 200 200
rdmpw3265m 14205 dbc440bd... releases/daemon-dbc440bd54b8/tyrelld 39–42 200 200
rdmpw3275m 79892 dbc440bd... releases/daemon-dbc440bd54b8/tyrelld 39–42 200 200
jdmbair13m5 53469 dbc440bd... releases/daemon-dbc440bd54b8/tyrelld 39–42 200 200

The rollback daemon is universal x86_64 arm64, Team Identifier ZU2882L4HT, Hardened Runtime enabled, and passes strict code-signature verification on all six hosts. This is prompt service containment only. Build 15 still has the previously documented long-duration high-RSS defect and must not be reported as a durable memory fix.

Bug and coordination records

Backups and undo

Outstanding work