rdmpw3275m-changelog-20260911-1649-tyrell-build18-source-correction
Corrected Tyrell's Build 18 repository-bundle plan so independent-clone and registered-worktree history is preserved without restoring the high-CPU duplicate-bundle behavior; canonical source review accepted the exact final commit, while runtime rollout remains gated.
Scope
- Host that changed local state:
rdmpw3275m. - Scratch worktree:
/Users/richh/dev/_worktrees/tyrell-build17-permission-cache-20260909. - Branch:
codex/tyrelld-permission-cache-20260909. - Canonical reviewer/build host:
rdmsm4x; work there was performed by the canonical Codex owner in its isolated handoff worktree. - No Build 18 binary was installed or launched on
rdmpw3275mduring this change.
Source changes
/Users/richh/dev/_worktrees/tyrell-build17-permission-cache-20260909/Sources/TyrellCore/RepoBundler.swift- Independent clones coalesce only when their complete ref-tip sets match.
- Same-HEAD clones with different private refs receive distinct bundle destinations.
- Existing bundle reuse requires proven ref coverage; replacement bundles are validated and hashed before a same-directory atomic rename.
- The prior valid bundle remains in place on bundle creation, coverage validation, hashing, or rename failure.
- Planning exposes missing ref-tip evidence, and registered alternate
worktree HEADs are enumerated using Git's
worktrees/<id>/HEADandmain-worktree/HEADbundle names.
/Users/richh/dev/_worktrees/tyrell-build17-permission-cache-20260909/Sources/tyrelld/ClientLoop.swift- Passes planned ref tips into spooling and suppresses all destructive snapshot pruning when an inventory root is partial or any valid-HEAD source lacks ref-tip evidence.
/Users/richh/dev/_worktrees/tyrell-build17-permission-cache-20260909/Tests/TyrellCoreTests/RepoBundlePassTests.swift- Added independent-clone private-ref, same-HEAD ref-only invalidation, failed replacement preservation, incomplete-plan pruning, and detached registered-worktree restoration regressions.
Git evidence
0b0065627c58f8107fc827bcd40aa4c34aa4ec56— initial independent-clone/ref-coverage correction.e9c990d5f00524a1df52e814675561599f8a921c— incomplete-planning fail-closed gate. One earlier ticket/message misstated the full object; corrective receipts record this verified object.bd4ae6e7e1fe9dea38d2b7fa3d584165939de961— final registered-worktree HEAD coverage correction.- The exact final head was pushed to
origin/codex/tyrelld-permission-cache-20260909; the worktree was clean and matched the remote afterward.
Commands and verification
git diff --check— passed before each commit.swift build --target TyrellCoreTests— passed after each correction; the final test target compiled successfully.swift build --target tyrelld— passed after each correction.swift run Harnessfrom/tmp/tyrell-ref-harness-20260911— seven runtime checks passed:- independent-clone private refs preserved;
- missing ref tips mark a pass incomplete;
- main and linked representatives enumerate alternate worktree HEADs;
- detached unreferenced worktree HEAD preserved;
- same-HEAD ref mutation replaces and re-hashes content;
- injected hash failure preserves the prior bundle;
- ref-coverage mismatch preserves the prior bundle.
- Full
swift teston this Intel host still stops in the pre-existing Apple Swift 6.3.3SettingsView.swiftIRGenSmallVector unable to growcompiler crash; this was not treated as a test failure or a pass. - Canonical independent review on
rdmsm4xaccepted exact sourcebd4ae6e7e1fe9dea38d2b7fa3d584165939de961: XCTest 358 with one skip and zero failures, Swift Testing 472 across 34 suites, and all three focused script contracts passed. - Read-only observation of the canonical Build 18 candidate found
build exit
0, valid strict code signatures, daemon SHA-256c4f17a2ec720f2be75099569990a13eed7bcef45d1e737cce8c1e72334176464, app executable SHA-25608b2dca07d10c82e2a65161f5b61682aa305d4ad0fb279d3c1ccb47a00a305f5, and daemon notarization statusAccepted. These are artifact observations, not runtime acceptance or fleet release. - Local rollback daemon remained the exact signed Build 15 object at
/Users/richh/Library/Application Support/Tyrell/releases/daemon-dbc440bd54b8/tyrelld, SHA-256dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0; PID 1820 served HTTP 200 on ports 43117 and 43118 with 41 open-file rows and 796 MB physical footprint.
Coordination and tickets
- Updated
ISSUE-20260911-01andISSUE-20260909-12with rejection, correction, exact-object, verification, and source-acceptance receipts. - Canonical review coordination used fleet thread
20260911-153559-5C88425Cand Codex task01a08a70-7b42-7ed1-aa30-1e3408453d0a. - Local agy manifest and status were unchanged, no exact
agyprocess existed, and no provider 429,RESOURCE_EXHAUSTED, or reset boundary appeared. Every discovered local parent remains complete or complete pending canonical acceptance, so no agy parent was incorrectly resumed.
Recovery and undo
- No destructive cleanup occurred and no prior bundle or installed daemon was replaced locally.
- To abandon the source candidate, leave the final branch unintegrated
or revert commits
bd4ae6e,e9c990d, and0b00656in that order on a new authorized branch; do not rewrite published history. - Runtime rollback remains the stable Build 15 daemon path and exact SHA-256 recorded above.
- The
/tmp/tyrell-ref-harness-20260911package is disposable validation scaffolding and is not a release artifact.
Outstanding gates
- Canonical owner must finish app notarization/stapling, provenance verification, integration, and rollback-protected canary launch.
- Build 18 runtime acceptance requires repeated full inventory evidence plus the existing minimum six-hour same-PID memory/descriptor/endpoint gate before any wider rollout.
TASK-20260906-01still awaits explicit canonical accept/reject/integration receipts for the locally completed agy handoffs; missing receipts are not permission to re-run completed parents.