rdmpw3275m-changelog-20260911-0519-tyrelld-fifth-high-rss-restart
rdmpw3275m changelog — fifth tyrelld Build 15 high-RSS restart
Recorded and escalated the fifth verified high-RSS containment
restart of the exact signed Tyrell Build 15 daemon on
rdmpw3275m; launchd recovered the unchanged rollback
artifact and both status planes, while the unsigned Build 18 fix
remained uninstalled behind the canonical signing and canary gates.
Scope and state change
- Host changed by the automated containment action:
rdmpw3275m. - Devmon terminated old
tyrelldPID48734at 2026-09-11 05:10:46 EDT after its configuredhigh_rsscondition fired. - Launchd recovered the daemon as PID
75606from the existing stable managed path. No source, database, configuration, LaunchAgent plist, GUI application, or candidate artifact was changed by this investigation. - Canonical
rdmsm4xwas inspected read-only. Its rollback daemon remained online as the same PID21749, and canonical Tyrell source main remained clean at53c0d8c17a4858fda4c182678e0baa823e603f77.
Evidence
- Fleet event:
20260911-051104-FC46FA53. - Incident directory:
/Users/richh/.devmon/incidents/20260911-051046-tyrelld-48734-high_rss. - Old process capture: PID
48734, elapsed15:31:05, ps RSS4,228,260 KB, and instantaneous CPU100.9%. - Memory measurements must remain distinct:
footprintmeasured 563 MB current physical footprint and 1.2 GB peak, not 4.1 GB physical memory.vmmapshowed 418 MB dirtyMALLOC_LARGE, 1.687 GB reclaimableMALLOC_LARGE_REUSABLE, 152 MB SQLite page cache, and 3.5 GB writable resident mappings. - The restricted
leaksscan reported zero detected leaked bytes but could not inspect writable memory, so it does not clear the retained-memory defect. - The incident open-file capture contained 41
lsofrows. Descriptor exhaustion was not the restart trigger. - The captured sample found the old process idle by the time sampling began, so the instantaneous 100.9% CPU value is not promoted into a sustained CPU diagnosis.
- Launchd logged temporary exit 75 data-port-busy retries while the
old listener was released, then converged on one running replacement. At
05:18 EDT,
launchctlreportedruns = 2,state = running, and PID75606. - Replacement artifact:
- managed symlink target:
/Users/richh/Library/Application Support/Tyrell/releases/daemon-dbc440bd54b8/tyrelld - SHA-256:
dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0 - architectures:
x86_64 arm64 - signing Team:
ZU2882L4HT - Hardened Runtime present
- managed symlink target:
- At 05:17 EDT, replacement PID
75606used 0.4% CPU, had 770 MB current physical footprint / 1,136 MB peak and 40lsofrows, and returned HTTP 200 on both43117/api/statusand43118/api/status. - On
rdmsm4x, the same rollback PID21749entered a later inventory pass at approximately 05:15 EDT. CPU was observed at 30.8–36.0%; a one-second sample showed 398 stacks inClientLoop.autoInventoryand 29 inProjectIdentity.rootCommit/Git work. CPU fell to 2.4% by 05:17. This is bounded repeated-pass activity evidence, not proof of another sustained runaway. Both hub status planes stayed HTTP 200 and the physical footprint was 41 MB current / 1,188 MB peak.
Ticket and coordination changes
- Reclaimed and updated
ISSUE-20260905-23with the fifth restart, exact memory-category evidence, replacement health, and artifact identity. - Updated
ISSUE-20260911-01with direct evidence that an unchanged Build 15 runtime still repeats per-root Git work on a later inventory pass. - Updated release gate
ISSUE-20260909-12; Build 18 remains blocked on full-inventory, repeated-unchanged-pass, long same-PID physical-memory/CPU/descriptor/socket, concurrent-permission, and reboot acceptance. - Sent high-priority canonical owner/canary escalation
20260911-051833-7DEC74B6, following request20260911-043153-E7DE1BDE. - No canonical acceptance, signed Build 18 artifact, or canary receipt had arrived at this checkpoint.
Source and build status
- Build 18 candidate source remains branch
codex/tyrelld-permission-cache-20260909at exact clean, pushed head9a0fe66f8fb7a3d8251d3340efc6467255bb7265. - The candidate includes stable daemon lifecycle, permission snapshot caching, shared-Git-store bundle coalescing, exact-path size-plus-mtime hash reuse, fewer Git probes, preservation of divergent clone snapshots, and fail-closed pruning after partial scans.
- Prior canonical Swift 6.4 validation passed all 468
TyrellCoreTests, focused new and existing regressions, all three release contracts, and universal Release builds. - Validation-only binaries are unsigned/ad-hoc and were not installed.
Their hashes remain:
- daemon:
b57cd0e51813f30386894857f20c428bb36772202d1d592c8cbe35ee8d5fe13f - app executable:
957660d2826b2b8d0bed51d2ac498dd2e8360276e1c2a1931f865d76de8bc52a
- daemon:
Commands used
agent_msg.zsh syncandagent_msg.zsh read 20260911-051104-FC46FA53ps,lsof,footprint,vmmap,leaks,sample,curl,readlink,shasum,lipo, andcodesigninspectionslaunchctl print gui/501/com.eastcoastscience.tyrelldticket search,ticket show,ticket claim,ticket comment, and ticket heartbeats- Read-only Git branch/ref/status checks on the isolated Build 18 branch and canonical main
Rollback and undo
- The active runtime is already the retained rollback. Keep
/Users/richh/Library/Application Support/Tyrell/releases/daemon-dbc440bd54b8/tyrelldand its managed symlink until an exact signed Build 18 candidate passes every canary gate. - No manual process rollback is required; devmon and launchd completed the recoverable restart. If the replacement loses either endpoint or accumulates descriptor pressure, preserve fresh diagnostics before another owner-controlled recovery.
- No source commit was created in this checkpoint. Existing Build 18 source changes can be reversed only on the isolated feature branch by reverting its feature commits; canonical main was untouched.
Outstanding actions
- A canonical owner must explicitly accept and review exact Build 18
head
9a0fe66, integrate it through an authorized isolated lane, build universal app and daemon artifacts onrdmsm4x, sign with TeamZU2882L4HTand Hardened Runtime, and notarize the GUI app. rdmbair15m5must canary the exact signed hashes through a complete inventory, at least one repeated unchanged pass, a long same-PID resource/socket/permission soak, and stable-path reboot recovery.- Only those exact accepted artifacts may be installed and launched on
rdmpw3275mor expanded fleet-wide. - The local agy monitor remains unchanged: no running
agyprocess, no eligible unfinished parent, no new provider quota denial/reset boundary, and no canonical acceptance receipt.