rdmpw3275m-changelog-20260911-1703-tyrell-build18-canary-launched
Filed and contained a TyrellBar launch-readiness bug, verified its canonical fix, and advanced the exact signed/notarized Tyrell Build 18 artifacts to a rollback-protected single-host canary with a durable six-hour guard.
Scope
- Coordinating host:
rdmpw3275m. - Canonical build/integration host:
rdmsm4x. - Designated canary only:
rdmbair15m5. - No fleet-wide promotion occurred.
rdmpw3275mremained on the exact Build 15 rollback daemon.
First canary failure and recovery
- First Build 18 app canary attempt returned exit 1 after the
TyrellBar readiness gate observed
/usr/libexec/xpcproxyduring the normal post-kickstart exec transition and rejected it immediately. - The installer restored Build 17 Tyrell.app and the canary guard
retained/restored exact Build 15 daemon SHA-256
dbc440bd54b85a54dd6c4150b23b3e508bff7d8d8080687d81b9ba7ac2cbbcf0. - Independent readback on
rdmbair15m5found the restored TyrellBar at its correct embedded executable path, Build 17 app executable SHA-2568693ebce3d474fed049597d11e3579bf1cd32f7a78acfd9544c78d77592da05e, exact Build 15 daemon identity, and HTTP 200 on ports 43117 and 43118.
Bug and canonical fix
- Filed canonical
ISSUE-20260911-11underISSUE-20260909-12: “TyrellBar canary rejects transient xpcproxy before exec readiness.” - Acceptance criteria require bounded grace only for the exact system xpcproxy path, immediate rejection of every other unexpected path, fail-closed rollback if the transition never completes, positive and stuck-proxy tests, and a repeated exact-identity canary.
- Canonical fix commit
1165c89a8f105c997c3633b33ba0d65a7bf09231passed 16 restart contract cases, including transition success and stuck-proxy rollback, plus five negative controls. - Pull request 27 merged the fix at
b2e45d04cb4154321a79f672fc841f702a60bf01.
Immutable Build 18 artifact evidence
- Canonical release source was already merged by pull request 26 at
2f0fe26f591199b3a556e9c7124cc34b74fdd9bb. - Tyrell.app executable SHA-256:
08b2dca07d10c82e2a65161f5b61682aa305d4ad0fb279d3c1ccb47a00a305f5. - tyrelld SHA-256:
c4f17a2ec720f2be75099569990a13eed7bcef45d1e737cce8c1e72334176464. - Both are signed Developer ID, Team
ZU2882L4HT, Hardened Runtime, and universalx86_64 arm64artifacts. - App notarization submission
89a4dce9-5a4f-4aaf-85f5-f843da03ee63and daemon submission6fc11aee-df99-4b0a-95fe-a79920de8717were both observedAccepted.
Canary retry 2
- Durable stage on
rdmbair15m5:/Users/richh/.tyrell/build18-canary-20260911-2f0fe26-retry2. - Guard PID at readback: 94369.
- Exact Build 18 Tyrell.app was installed and launched from
/Applications/Tyrell.app. - Exact daemon stable target:
/Users/richh/Library/Application Support/Tyrell/releases/daemon-c4f17a2ec720/tyrelld. - Initial daemon PID: 94501; both status planes returned HTTP 200.
- Early sample: physical footprint about 50 MiB, peak about 551 MiB, 41-44 open-file rows. A later 44% CPU sample occurred during inventory and is neither pass nor failure by itself.
- Guard state was
soaking; the long same-PID decision boundary is epoch1789182530.9299772, approximately 2026-09-11 23:08 EDT. At least one complete inventory and a repeated unchanged pass are also required.
Commands and verification
- Read canonical release and canary receipts over authenticated fleet SSH without modifying peer worktrees.
- Re-ran exact SHA-256,
codesign --verify --deep --strict, Info.plist build/version,launchctl, live process-path, endpoint, descriptor, and physical-footprint checks. - Queried
/Users/richh/.tyrell/build18-canary-20260911-2f0fe26-retry2/state.json,latest.json,samples.jsonl, installer logs, and rollback evidence. - Updated recurring automation
finish-tyrell-build-16with exact source, merge, artifact, notarization, bug-fix, canary-stage, guard, decision-boundary, rollback, and local-agy state. It remains active every 15 minutes and quiet while state is merely healthy/pending.
Recovery and undo
- The canary stage retains the exact prior daemon and plist under its
prior/directory and owns a fail-closed guard; do not manually bypass it. - Exact Build 15 remains the known daemon rollback identity across the fleet.
- If the canary violates CPU, physical-memory, descriptor, socket, endpoint, permissions, inventory, PID-continuity, or elapsed-time policy, preserve its receipt and allow the guard to restore the prior app/daemon state.
Outstanding gates
- Do not claim runtime acceptance until the same daemon PID survives the full warm-up plus six-hour soak, complete inventory, and repeated unchanged-pass checks and the guard emits an explicit passing receipt.
- Independently reproduce that receipt before any next-host installation. There is no automatic fleet expansion.
- The local agy track remains unchanged: no running agy process, no verified provider quota denial/reset boundary, and completed parent handoffs still awaiting canonical receipts.